CVE-2025-48965: Null Pointer Dereference
Published Jul 20, 2025
·Updated
Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtlsasn1storenameddata can trigger conflicting data with val.p of NULL but val.len greater than zero.
Affected Software
2 affected components
Mbed TLS Mbed TLS<3.6.4
Arm mbed TLS<3.6.4
Event History
Jul 20, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-48965?
CVE-2025-48965 has a moderate severity due to the potential for a NULL pointer dereference affecting application stability.
2
How do I fix CVE-2025-48965?
To fix CVE-2025-48965, upgrade Mbed TLS to version 3.6.4 or later.
3
What software versions are affected by CVE-2025-48965?
Mbed TLS versions before 3.6.4 are affected by CVE-2025-48965.
4
Are there any workarounds for CVE-2025-48965?
There are no recommended workarounds for CVE-2025-48965, and updating is necessary to address the issue.
5
What could happen if CVE-2025-48965 is exploited?
If exploited, CVE-2025-48965 could lead to application crashes due to the NULL pointer dereference.