CVE-2025-65501: Null Pointer Dereference
Published Nov 24, 2025
·Updated
Null pointer dereference in coapdtlsinfocallback() in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a DTLS handshake where SSLgetappdata() returns NULL.
Affected Software
2 affected components
OISM libcoap=4.3.5
libcoap libcoap=4.3.5
Event History
Nov 24, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-65501?
CVE-2025-65501 is classified as a denial of service vulnerability affecting OISM libcoap 4.3.5.
2
How does CVE-2025-65501 affect OISM libcoap?
CVE-2025-65501 allows remote attackers to cause a denial of service via a null pointer dereference during a DTLS handshake.
3
How do I fix CVE-2025-65501?
To fix CVE-2025-65501, upgrade OISM libcoap to a version that addresses this vulnerability.
4
What functions are involved in CVE-2025-65501?
The vulnerability in CVE-2025-65501 is triggered during the execution of the coap_dtls_info_callback() and involves the SSL_get_app_data() function.
5
Can CVE-2025-65501 be exploited remotely?
Yes, CVE-2025-65501 can be exploited remotely by attackers attempting to perform a DTLS handshake.