CVE-2025-8865: Null Pointer Dereference
The YugabyteDB tablet server contains a flaw in its YCQL query handling that can trigger a null pointer dereference when processing certain malformed inputs. An authenticated attacker could exploit this issue to crash the YCQL tablet server, resulting in a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8865?
CVE-2025-8865 has a severity rating that indicates it can lead to a denial of service due to a null pointer dereference.
How do I fix CVE-2025-8865?
To remediate CVE-2025-8865, ensure you are using the latest version of YugabyteDB where the issue has been addressed.
What components of YugabyteDB are affected by CVE-2025-8865?
CVE-2025-8865 specifically affects the YCQL tablet server in YugabyteDB.
Can CVE-2025-8865 be exploited remotely?
CVE-2025-8865 requires authenticated access to the YCQL tablet server for exploitation.
What impact does CVE-2025-8865 have on system availability?
The exploitation of CVE-2025-8865 can lead to a denial of service, causing the YCQL tablet server to crash.