Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. In versions prior to commit 36f70d1, the Curve25519Add and Curve25519ScalarMul precompiles incorrectly handle invalid Ristretto point representations. Instead of returning an error, they silently treat invalid input bytes as the Ristretto identity element, leading to potentially incorrect cryptographic results. This is fixed in commit 36f70d1.
History

Tue, 29 Jul 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Polkadot
Polkadot frontier
Vendors & Products Polkadot
Polkadot frontier

Mon, 28 Jul 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Jul 2025 20:30:00 +0000

Type Values Removed Values Added
Description Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. In versions prior to commit 36f70d1, the Curve25519Add and Curve25519ScalarMul precompiles incorrectly handle invalid Ristretto point representations. Instead of returning an error, they silently treat invalid input bytes as the Ristretto identity element, leading to potentially incorrect cryptographic results. This is fixed in commit 36f70d1.
Title Polkadot Frontier contains silent failure in Curve25519 arithmetic precompiles with malformed points
Weaknesses CWE-327
References
Metrics cvssV4_0

{'score': 9.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-07-28T20:08:22.886Z

Updated: 2025-07-28T20:26:18.866Z

Reserved: 2025-07-21T23:18:10.282Z

Link: CVE-2025-54426

cve-icon Vulnrichment

Updated: 2025-07-28T20:26:04.280Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-28T21:15:26.887

Modified: 2025-07-29T14:14:29.590

Link: CVE-2025-54426

cve-icon Redhat

No data.