CVE-2025-48965

Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_asn1_store_named_data can trigger conflicting data with val.p of NULL but val.len greater than zero.
Configurations

Configuration 1 (hide)

cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:*

History

07 Aug 2025, 01:14

Type Values Removed Values Added
First Time Arm mbed Tls
Arm
References () https://github.com/Mbed-TLS/mbedtls-docs/blob/main/security-advisories/mbedtls-security-advisory-2025-06-6.md - () https://github.com/Mbed-TLS/mbedtls-docs/blob/main/security-advisories/mbedtls-security-advisory-2025-06-6.md - Third Party Advisory, Mitigation
References () https://mbed-tls.readthedocs.io/en/latest/tech-updates/security-advisories/ - () https://mbed-tls.readthedocs.io/en/latest/tech-updates/security-advisories/ - Vendor Advisory
CPE cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:*
CWE CWE-476

22 Jul 2025, 13:06

Type Values Removed Values Added
Summary
  • (es) Mbed TLS anterior a 3.6.4 tiene una desreferencia de puntero NULL porque mbedtls_asn1_store_named_data puede generar datos conflictivos con val.p de NULL pero val.len mayor que cero.

20 Jul 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-20 18:15

Updated : 2025-08-07 01:14


NVD link : CVE-2025-48965

Mitre link : CVE-2025-48965

CVE.ORG link : CVE-2025-48965


JSON object : View

Products Affected

arm

  • mbed_tls
CWE
CWE-696

Incorrect Behavior Order

CWE-476

NULL Pointer Dereference