CVE-2025-65493: Null Pointer Dereference
Published Nov 24, 2025
·Updated
NULL pointer dereference in src/coapopenssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS/TLS connection that triggers BIOgetdata() to return NULL.
Affected Software
2 affected components
OISM libcoap
libcoap libcoap=4.3.5
Remediation
Patch Available
Event History
Nov 24, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-65493?
CVE-2025-65493 has a moderate severity level as it can lead to denial of service due to a NULL pointer dereference.
2
How do I fix CVE-2025-65493?
To fix CVE-2025-65493, update OISM libcoap to the latest version that addresses this vulnerability.
3
What software is affected by CVE-2025-65493?
CVE-2025-65493 affects OISM libcoap version 4.3.5.
4
Can CVE-2025-65493 be exploited remotely?
Yes, CVE-2025-65493 can be exploited remotely through a crafted DTLS/TLS connection.
5
What kind of attack does CVE-2025-65493 enable?
CVE-2025-65493 enables a denial of service attack by causing a crash via NULL pointer dereference.