Summary
risc0 vulnerable to arbitrary code execution in guest via memory safety failure in sys_read
Arbitrary code execution in guest via memory safety failure in sys_read
In affected versions of risc0-zkvm-platform, when the zkVM guest calls sys_read, the host is able to use a crafted response to write to an arbitrary memory location in the guest. This capability can be leveraged to execute arbitrary code within the guest. As sys_read is the mechanism by which input is requested by the guest, all guest programs built with the affected versions are vulnerable. This critically compromises the soundness guarantees of the guest program.
A fix was applied in #3351. The vulnerable pointer arithmetic was removed, and replaced with a simplified implementation in the v1compat kernel which uses Rust’s slice functions to guarantee memory safety.
The fix has been released as part of risc0-zkvm versions 2.3.2 and 3.0.3. All prior versions are affected.
Impact
Untrusted input is evaluated as executable code within the application's runtime environment. Typical impact: arbitrary code execution within the application's privilege context.
Affected versions
Security releases
Kodem intelligence
Severity tells you how bad this could be in the worst case. It does not tell you whether you are exposed. Exploitability and impact are functions of runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A vulnerable package can sit in your dependency tree and never run.
Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter. Kodem's runtime-powered SCA identifies whether this CVE is reachable in your applications.
Already deployed Kodem?
See it in your environmentNew to Kodem? Get a demo →Remediation advice
All developers of zkVM applications should update their guests to use risc0-zkvm versions ^2.3.2 or ^3.0.3.
This upgrade can be accomplished by editing all Cargo.toml files in the following way.
- Any references to
risc0-zkvmshould use version specifiers”2.3.2”or”3.0.3”. - Any references to
risc0-buildshould use version specifiers”2.3.2”or”3.0.3”, matchingrisc0-zkvm. - Any references to
risc0-zkvm-platformshould use version specifier”2.1.0”or later. Most projects will not have direct references to this crate.
Rebuild your application including the guest. You can run the following command to check that the patch is applied:
# Provide the path to your guest Cargo.toml. Should report risc0-zkvm-platform >=v2.1.0
cargo tree --depth 0 -p risc0-zkvm-platform --manifest-path path/to/methods/guest/Cargo.toml
Any applications that use the image ID of this guest need to be updated with the newly built image ID.
Note that there are no changes to the RISC Zero proof system or circuits. Provers are not required to take any action. Users of the Groth16 smart contract verifier and the RISC Zero Verifier Router are not required to take any action beyond updating their guest programs.
Any applications using the risc0-aggregation crate or the RiscZeroSetVerifier smart contract should update to version >=0.9. This application includes a zkVM guest, which is vulnerable in versions prior to 0.9. Instances of the RiscZeroSetVerifier operated by RISC Zero have been disabled via the estop mechanism outlined in the Verifier Management Design.
Frequently Asked Questions
- What is CVE-2025-61588? CVE-2025-61588 is a critical-severity code injection vulnerability in risc0-zkvm-platform (rust), affecting versions < 2.1.0. It is fixed in 2.1.0, 0.9, 2.3.2, 3.0.3. Untrusted input is evaluated as executable code within the application's runtime environment.
- Which packages are affected by CVE-2025-61588?
risc0-zkvm-platform(rust) (versions < 2.1.0)risc0-zkos-v1compat(rust) (versions < 2.1.0)risc0-aggregation(rust) (versions < 0.9)risc0-zkvm(rust) (versions < 2.3.2)
- Is there a fix for CVE-2025-61588? Yes. CVE-2025-61588 is fixed in 2.1.0, 0.9, 2.3.2, 3.0.3. Upgrade to this version or later.
- Is CVE-2025-61588 exploitable, and should I be worried? Whether CVE-2025-61588 is exploitable in your environment depends on whether the vulnerable code is present and reachable. A CVSS score is a worst-case rating; it does not account for your specific deployment, configuration, or usage patterns. Kodem, an Intelligent Application Security platform, uses runtime intelligence to show which vulnerabilities actually execute in production, so you can focus on the ones that represent real risk. Get a demo
- What actually determines whether CVE-2025-61588 is exploitable, and how bad it is? Exploitability and impact are not fixed properties of a CVE. They depend on runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A high CVSS score on a dependency that never runs is not the same as real risk. Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter.
- How do I fix CVE-2025-61588?
- Upgrade
risc0-zkvm-platformto 2.1.0 or later - Upgrade
risc0-zkos-v1compatto 2.1.0 or later - Upgrade
risc0-aggregationto 0.9 or later - Upgrade
risc0-zkvmto 2.3.2 or later - Upgrade
risc0-zkvmto 3.0.3 or later
- Upgrade