Junglewise Threat Intelligence

CVE-2026-72714: Rocq Prover kernel soundness bug in universe checking state desynchronization

CVE-2026-72714 · Severity: medium · CVSS 6.3 · Published 2026-08-24

Technologies: Rocq Prover. Vendors: Rocq.

Executive brief

Rocq Prover, an interactive theorem proving system used for formal verification of software and mathematics, has a critical flaw in how it manages universe checking rules within modules. When a module locally disables universe checking, the setting is not properly restored when the module closes, causing the kernel to accept mathematically unsound proofs that violate fundamental logical constraints. This allows attackers to prove false statements (like "0 = 1") without using any unsafe features, potentially invalidating all formally verified software that relied on proofs created in affected environments.

Technical details

This vulnerability is a state desynchronization bug (CWE-488) in the module system of Rocq Prover. The universe graph (ugraph) maintains its own copy of the universe checking flag independently of the global state. When "Local Unset Universe Checking" is used inside a module, both the global state and ugraph flag are modified. However, when the module closes, only the global state is restored from the saved module state; the ugraph's copy remains disabled. This creates a desync: Test Universe Checking reports the flag as enabled (reading global state) while the kernel continues accepting universe-inconsistent terms (using the stale ugraph flag). An attacker can exploit this by constraining two universes to be ordered, then disabling checks in a module, allowing them to treat universes as equal after module closure. This enables Hurkels' paradox, which derives a proof of False from the type-level contradiction. The exploit requires no axioms, plugins, or unsafe features, and the proof appears sound under Print Assumptions. No patch is currently available.

Affected products

  • Rocq Rocq Prover ≤ 9.2.0 and Coq 8.x (all versions with Hurkels in stdlib)

Timeline

  • 2026-08-24: disclosed
  • 2026-08-16: other: Issue reported as open with no fix available

References

Related threats