CVE-2025-65499: Out-of-bounds Read
Published Nov 24, 2025
·Updated
Array index error in tlsverifycallback() in src/coapopenssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSLgetexdataX509STORECTXidx() to return -1.
Affected Software
2 affected components
OISM libcoap=4.3.5
libcoap libcoap=4.3.5
Remediation
Patch Available
Event History
Nov 24, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-65499?
CVE-2025-65499 is categorized as a denial of service vulnerability due to an array index error.
2
How do I fix CVE-2025-65499?
To fix CVE-2025-65499, upgrade to version 4.3.6 or later of OISM libcoap.
3
What causes the CVE-2025-65499 vulnerability?
CVE-2025-65499 arises from an array index error in the tls_verify_call_back() function during a DTLS handshake.
4
Can CVE-2025-65499 be exploited remotely?
Yes, CVE-2025-65499 can be exploited by remote attackers through a crafted DTLS handshake.
5
Which version of OISM libcoap is affected by CVE-2025-65499?
OISM libcoap version 4.3.5 is affected by CVE-2025-65499.