Introducing Wiz for Exposure Management: Unify, prioritize, and remediate exposures everywhere.

CVE-2025-54873
Rust vulnerability analysis and mitigation

Overview

CVE-2025-54873 is a moderate severity vulnerability affecting the RISC Zero cryptographic system, specifically impacting multiple cargo packages including risc0-circuit-rv32im, risc0-circuit-rv32im-sys, and risc0-zkvm. The vulnerability was discovered in 2025 and affects versions 2.0 through 3.0 of the affected packages (GitHub Advisory).

Technical details

The vulnerability consists of two distinct issues in the division operation implementation: 1) For certain inputs to signed integer division, the circuit allowed two possible outputs, with only one being valid, and 2) The result of division by zero operations was underconstrained. The vulnerability was identified using the Picus tool from Veridise (GitHub Advisory).

Impact

The vulnerability affects the integrity of cryptographic operations in the RISC Zero system. Impacted on-chain verifiers had to be disabled via the estop mechanism outlined in the Verifier Management Design (GitHub Advisory).

Mitigation and workarounds

Users are recommended to upgrade to patched versions: risc0-zkvm users should upgrade to version 2.2.0 or later, while risc0-circuit-rv32im and risc0-circuit-rv32im-sys users should upgrade to version 3.0.0. Smart contract applications using the official RISC Zero Verifier Router do not need to take action as zkVM version 2.2 is active on all official routers. However, smart contract applications not using the verifier router should update their contracts to send verification calls to the 2.2 version of the verifier (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management