PT-2025-30210 · Mbed Tls+3 · Mbed Tls+3
Linh Le
+1
·
Published
2025-01-01
·
Updated
2026-05-05
·
CVE-2025-48965
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
mbedtls versions prior to 3.6.4
Description
The software contains a NULL pointer dereference issue in the
mbedtls asn1 store named data function. This occurs when conflicting data is triggered with val.p being NULL but val.len being greater than zero.Recommendations
Update to version 3.6.4 or later.
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Linuxmint
Ubuntu
Mbed Tls