CVE-2025-65411: Null Pointer Dereference
Published Dec 30, 2025
·Updated
A NULL pointer dereference in the src/path.c component of GNU Unrtf v0.21.10 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the searchpath parameter.
Affected Software
2 affected components
GNU unrtf
Unrtf Project Unrtf=0.21.10
Event History
Dec 30, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-65411?
CVE-2025-65411 has a high severity due to its potential to cause a Denial of Service (DoS).
2
How do I fix CVE-2025-65411?
To fix CVE-2025-65411, update to the latest version of GNU Unrtf that addresses the NULL pointer dereference vulnerability.
3
What component is affected in CVE-2025-65411?
CVE-2025-65411 affects the src/path.c component of GNU Unrtf v0.21.10.
4
What attack vector is exploited in CVE-2025-65411?
CVE-2025-65411 can be exploited by injecting a crafted payload into the search_path parameter.
5
What is the impact of exploiting CVE-2025-65411?
Exploiting CVE-2025-65411 can lead to a Denial of Service, disrupting the availability of the application.