{"id":"CVE-2025-70956","details":"A State Pollution vulnerability was discovered in the TON Virtual Machine (TVM) before v2025.04. The issue exists in the RUNVM instruction logic (VmState::run_child_vm), which is responsible for initializing child virtual machines. The operation moves critical resources (specifically libraries and log) from the parent state to a new child state in a non-atomic manner. If an Out-of-Gas (OOG) exception occurs after resources are moved but before the state transition is finalized, the parent VM retains a corrupted state where these resources are emptied/invalid. Because RUNVM supports gas isolation, the parent VM continues execution with this corrupted state, leading to unexpected behavior or denial of service within the contract's context.","modified":"2026-08-12T15:15:00.485170Z","published":"2026-02-13T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/70xxx/CVE-2025-70956.json"},"references":[{"type":"WEB","url":"https://gist.github.com/Lucian-code233/beab9d14683ed2bdf5543be430b91c70"},{"type":"WEB","url":"https://github.com/ton-blockchain/ton/releases/tag/v2025.04#:~:text=Arayz%2C%20Robinlzw%2C%20%40wy666444%20%40Lucian-code233"},{"type":"WEB","url":"https://mp.weixin.qq.com/s/ZD35baKUikefFdtNHZIC9g"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/70xxx/CVE-2025-70956.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-70956"},{"type":"FIX","url":"https://github.com/ton-blockchain/ton/commit/1835d84602bbaaa1593270d7ab3bb0b499920416"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ton-blockchain/ton","events":[{"introduced":"0"},{"fixed":"cee4c674ea999fecc072968677a34a7545ac9c4d"},{"fixed":"1835d84602bbaaa1593270d7ab3bb0b499920416"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"v2025.04"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["tolk-0.10","v2025.03","tolk-0.9","v2025.02","tolk-0.8","tolk0.7","v2024.12-1","func-0.4.6","v2024.12-alpha","v2024.10","func-0.4.5","v2024.09","v2024.08","v2024.06","v2024.04","v2024.03","v2024.02","v2024.01","v2023.12","v2023.11","v2023.10","perfomance-test","v2023.06","v2023.05","func-0.4.4","v2023.04","func-0.4.3","v2023.03","func-0.4.2","v2023.01","func-0.4.1","v2022.12","func-0.4.0","v2022.10","func-0.3.0","v2022.09","v2022.08","func-0.2.0","v2022.06","v2022.05","func-0.1.0","newton-end","newton-start","func-0.0.99"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-70956.json","vanir_signatures_modified":"2026-08-12T15:15:00Z","vanir_signatures":[{"source":"https://github.com/ton-blockchain/ton/commit/1835d84602bbaaa1593270d7ab3bb0b499920416","target":{"file":"crypto/vm/vm.cpp","function":"VmState::run_child_vm"},"deprecated":false,"digest":{"function_hash":"29324889744851572738815809274921750128","length":1112},"id":"CVE-2025-70956-6d1fc490","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"line_hashes":["53894155880948149276052901331365173357","79104320538571693451214850926176828564","307083205793735348047708172252774912473","231488853471609936760833955600202851377"],"threshold":0.9},"id":"CVE-2025-70956-8d510ee1","signature_type":"Line","signature_version":"v1","source":"https://github.com/ton-blockchain/ton/commit/1835d84602bbaaa1593270d7ab3bb0b499920416","target":{"file":"crypto/vm/vm.cpp"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}