CVE-2025-24802

CVSS 3.1 Score 8.6 of 10 (high)

Details

Published Jan 30, 2025
CWE ID 1240

Summary

CVE-2025-24802 is a vulnerability affecting the Plonky2 SNARK implementation, which is based on PLONK and FRI techniques. The issue lies in the lookup tables used by the implementation, which always include the input-output pair 0 -> 0. Malicious provers can exploit this by proving that a function f(0) = 0 for any lookup table f, except those whose length is divisible by 26. This issue is due to the padding of LookupTableGates with zeros. Users can work around this vulnerability by extending the table length to make it divisible by 26. The vulnerability has been addressed in version 1.0.1 of Plonky2.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share