CVE-2025-65496: Null Pointer Dereference
NULL pointer dereference in coapdtlsgeneratecookie() in src/coapopenssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSLgetSSLCTX() to return NULL.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-65496?
CVE-2025-65496 has a high severity rating, as it allows remote attackers to cause a denial of service.
How do I fix CVE-2025-65496?
To fix CVE-2025-65496, update to the latest version of OISM libcoap where the vulnerability has been addressed.
What causes the vulnerability CVE-2025-65496?
CVE-2025-65496 is caused by a NULL pointer dereference in the coap_dtls_generate_cookie function during a crafted DTLS handshake.
What impact does CVE-2025-65496 have on affected software?
CVE-2025-65496 can lead to a denial of service, making affected systems unresponsive to legitimate requests.
Who is affected by CVE-2025-65496?
CVE-2025-65496 affects users of OISM libcoap version 4.3.5 and potentially older versions.