CVE-2025-58359 - CVE House
Back to Database
Status published Medium CVE-2025-58359

frost-core: refresh shares with smaller min_signers will reduce group security

Vulnerability Description

ZF FROST is a Rust implementation of FROST (Flexible Round-Optimised Schnorr Threshold signatures). In versions 2.0.0 through 2.1.0, refresh shares with smaller min_signers will reduce security of group. The inability to change min_signers (i.e. the threshold) with the refresh share functionality (frost_core::keys::refresh module) was not made clear to users. Using a smaller value would not decrease the threshold, and attempts to sign using a smaller threshold would fail. Additionally, after refreshing the shares with a smaller threshold, it would still be possible to sign with the original threshold, potentially causing a security loss to the participant's shares. This issue is fixed in version 2.2.0.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-58359

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

ZcashFoundation

View all reports →

Affected Software

frost
Vulnerable Versions:
>= 2.0.0, < 2.2.0

Timeline

Official Publish: September 4th, 2025
Last Modified: September 5th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.