CVE Vulnerabilities

CVE-2025-48965

Incorrect Behavior Order

Published: Jul 20, 2025 | Modified: Aug 07, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_asn1_store_named_data can trigger conflicting data with val.p of NULL but val.len greater than zero.

Weakness

The product performs multiple related behaviors, but the behaviors are performed in the wrong order in ways which may produce resultant weaknesses.

Affected Software

Name Vendor Start Version End Version
Mbed_tls Arm * 3.6.4 (excluding)
Mbedtls Ubuntu upstream *

References