CVE-2025-65498: Null Pointer Dereference
Published Nov 24, 2025
·Updated
NULL pointer dereference in coapdtlsgeneratecookie() in src/coapopenssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSLgetSSLCTX() to return NULL.
Affected Software
2 affected components
OISM libcoap
libcoap libcoap=4.3.5
Remediation
Patch Available
Event History
Nov 24, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-65498?
CVE-2025-65498 is classified as a denial of service vulnerability.
2
How do I fix CVE-2025-65498?
To fix CVE-2025-65498, upgrade to the latest version of OISM libcoap that includes patches for this vulnerability.
3
What causes the CVE-2025-65498 vulnerability?
CVE-2025-65498 is caused by a NULL pointer dereference in the coap_dtls_generate_cookie() function during a DTLS handshake.
4
Who is affected by CVE-2025-65498?
CVE-2025-65498 affects users of OISM libcoap version 4.3.5.
5
What impact does CVE-2025-65498 have on systems?
CVE-2025-65498 may allow remote attackers to crash applications using OISM libcoap by exploiting the vulnerability during DTLS handshakes.