CVE Vulnerabilities

CVE-2025-48965

Incorrect Behavior Order

Published: Jul 20, 2025 | Modified: Nov 03, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_asn1_store_named_data can trigger conflicting data with val.p of NULL but val.len greater than zero.

Weakness

The product performs multiple related behaviors, but the behaviors are performed in the wrong order in ways that may produce resultant weaknesses.

Affected Software

NameVendorStart VersionEnd Version
Mbed_tlsArm*3.6.4 (excluding)
MbedtlsUbuntudevel*
MbedtlsUbuntuesm-apps/bionic*
MbedtlsUbuntuesm-apps/focal*
MbedtlsUbuntuesm-apps/jammy*
MbedtlsUbuntuesm-apps/noble*
MbedtlsUbuntuesm-apps/xenial*
MbedtlsUbuntujammy*
MbedtlsUbuntunoble*
MbedtlsUbuntuplucky*
MbedtlsUbuntuquesting*
MbedtlsUbuntuupstream*

References