CVE-2025-58359
ZF FROST is a Rust implementation of FROST (Flexible Round-Optimised Schnorr Threshold signatures). In versions 2.0.0 through 2.1.0, refresh shares with smaller min_signers will reduce security of group. The inability to change min_signers (i.e. the threshold) with the refresh share functionality (frost_core::keys::refresh module) was not made clear to users. Using a smaller value would not decrease the threshold, and attempts to sign using a smaller threshold would fail. Additionally, after refreshing the shares with a smaller threshold, it would still be possible to sign with the original threshold, potentially causing a security loss to the participant's shares. This issue is fixed in version 2.2.0.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.29%
- CWE
- CWE-325
- Published
- 2025-09-04
- Last modified
- 2026-03-13
Affected products
- ZcashFoundation frost
Weakness type
Related vulnerabilities
- CVE-2026-25250 — EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step"...
- CVE-2026-76784 — Insufficient Cryptographic Protections in Local Device Communication Protocol on Multiple TP-Link Kasa Smart Home Devices
- CVE-2026-59776 — Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or...
- CVE-2026-58638 — Windows Boot Loader Security Feature Bypass Vulnerability
- CVE-2026-55144 — Windows Cryptography API: Next Generation (CNG) Tampering Vulnerability
- CVE-2026-6458 — AES-256-GCM Authentication Tag Does Not Cover First Ciphertext Blocks When AAD Is Empty
- CVE-2026-49440 — Deno: Miller-Rabin Primality Test Allows Zero Rounds
- CVE-2026-9266 — A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux...