RISC Zero is a zero-knowledge verifiable general computing platform based on zk-STARKs and the RISC-V microarchitecture. RISC packages risc0-zkvm versions 2.0.0 through 2.1.0 and risc0-circuit-rv32im and risc0-circuit-rv32im-sys versions 2.0.0 through 2.0.4 contain vulnerabilities where signed integer division allows multiple outputs for certain inputs with only one being valid, and division by zero results are underconstrained. This issue is fixed in risc0-zkvm version 2.2.0 and version 3.0.0 for the risc0-circuit-rv32im and risc0-circuit-rv32im-sys packages.
Metrics
Affected Vendors & Products
References
History
Thu, 07 Aug 2025 07:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Risc Zero Project
Risc Zero Project risc Zero |
|
Vendors & Products |
Risc Zero Project
Risc Zero Project risc Zero |
Wed, 06 Aug 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 05 Aug 2025 23:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | RISC Zero is a zero-knowledge verifiable general computing platform based on zk-STARKs and the RISC-V microarchitecture. RISC packages risc0-zkvm versions 2.0.0 through 2.1.0 and risc0-circuit-rv32im and risc0-circuit-rv32im-sys versions 2.0.0 through 2.0.4 contain vulnerabilities where signed integer division allows multiple outputs for certain inputs with only one being valid, and division by zero results are underconstrained. This issue is fixed in risc0-zkvm version 2.2.0 and version 3.0.0 for the risc0-circuit-rv32im and risc0-circuit-rv32im-sys packages. | |
Title | RISC Zero Underconstrained Vulnerability: Division | |
Weaknesses | CWE-369 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-05T23:35:09.208Z
Updated: 2025-08-06T13:53:46.107Z
Reserved: 2025-07-31T17:23:33.473Z
Link: CVE-2025-54873

Updated: 2025-08-06T13:53:43.042Z

Status : Awaiting Analysis
Published: 2025-08-06T00:15:31.523
Modified: 2025-08-06T20:23:37.600
Link: CVE-2025-54873

No data.