CVE-2025-70954 Details
Description
A Null Pointer Dereference vulnerability exists in the TON Virtual Machine (TVM) within the TON Blockchain before v2025.06. The issue is located in the execution logic of the INMSGPARAM instruction, where the program fails to validate if a specific pointer is null before accessing it. By sending a malicious transaction or smart contract, an attacker can trigger this null pointer dereference, causing the validator node process to crash (segmentation fault). This results in a Denial of Service (DoS) affecting the availability of the entire blockchain network.
A null pointer dereference vulnerability has been identified in the TON Virtual Machine (TVM) within the TON Blockchain, affecting all versions prior to v2025.06. The vulnerability arises in the execution logic of the 'INMSGPARAM' instruction, where the program does not properly validate whether a pointer is null before accessing it. This oversight allows an attacker to send a malicious transaction or smart contract that triggers the null pointer dereference, causing the validator node process to crash with a segmentation fault. As a result, this vulnerability leads to a denial-of-service condition that impacts the availability of the entire blockchain network.
Users can upgrade to TON Blockchain version v2025.06 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 13, 2026CISA-ADP
Assessed Feb 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| TON Virtual Machine | All versions |
CPE
Remediation
| |
| TON Blockchain | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 17, 2026 | CVE Modified | CISA-ADP |
| Feb 17, 2026 | CVE Modified | CISA-ADP |
| Feb 13, 2026 | New CVE Received | [email protected] |
Volerion