CVE-2025-48965

Name
CVE-2025-48965
Description
Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_asn1_store_named_data can trigger conflicting data with val.p of NULL but val.len greater than zero.
NVD Severity
low
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://github.com/Mbed-TLS/mbedtls-docs/blob/main/security-advisories/mbedtls-security-advisory-2025-06-6.md
cve@mitre.org https://mbed-tls.readthedocs.io/en/latest/tech-updates/security-advisories/
af854a3a-2127-422b-91ae-364da2661108 https://lists.debian.org/debian-lts-announce/2025/08/msg00013.html

Match rules

CPE URI Source package Min version Max version
mbedtls >= 0 < 3.6.4

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
mbedtls edge-main 3.6.4-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
mbedtls edge-main 3.6.3.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mbedtls edge-main 3.6.3-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mbedtls edge-main 3.6.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mbedtls edge-main 3.6.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mbedtls edge-main 2.7.0-r0 None possibly vulnerable
mbedtls edge-main 2.6.0-r0 None possibly vulnerable
mbedtls edge-main 2.4.2-r0 None possibly vulnerable
mbedtls edge-main 2.28.8-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mbedtls edge-main 2.28.7-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mbedtls edge-main 2.28.5-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mbedtls edge-main 2.28.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mbedtls edge-main 2.16.8-r0 None possibly vulnerable
mbedtls edge-main 2.16.6-r0 None possibly vulnerable
mbedtls edge-main 2.16.4-r0 None possibly vulnerable
mbedtls edge-main 2.16.3-r0 None possibly vulnerable
mbedtls edge-main 2.16.12-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mbedtls edge-main 2.14.1-r0 None possibly vulnerable
mbedtls edge-main 2.12.0-r0 None possibly vulnerable
mbedtls 3.22-main 3.6.4-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
mbedtls 3.22-main 3.6.3.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mbedtls 3.22-main 3.6.3-r0 None possibly vulnerable
mbedtls 3.22-main 3.6.2-r0 None possibly vulnerable
mbedtls 3.22-main 3.6.1-r0 None possibly vulnerable
mbedtls 3.22-main 2.7.0-r0 None possibly vulnerable
mbedtls 3.22-main 2.6.0-r0 None possibly vulnerable
mbedtls 3.22-main 2.4.2-r0 None possibly vulnerable
mbedtls 3.22-main 2.28.8-r0 None possibly vulnerable
mbedtls 3.22-main 2.28.7-r0 None possibly vulnerable
mbedtls 3.22-main 2.28.5-r0 None possibly vulnerable
mbedtls 3.22-main 2.28.1-r0 None possibly vulnerable
mbedtls 3.22-main 2.16.8-r0 None possibly vulnerable
mbedtls 3.22-main 2.16.6-r0 None possibly vulnerable
mbedtls 3.22-main 2.16.4-r0 None possibly vulnerable
mbedtls 3.22-main 2.16.3-r0 None possibly vulnerable
mbedtls 3.22-main 2.16.12-r0 None possibly vulnerable
mbedtls 3.22-main 2.14.1-r0 None possibly vulnerable
mbedtls 3.22-main 2.12.0-r0 None possibly vulnerable
mbedtls 3.21-main 3.6.4-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
mbedtls 3.21-main 3.6.3-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mbedtls 3.21-main 3.6.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mbedtls 3.21-main 3.6.1-r0 None possibly vulnerable
mbedtls 3.21-main 2.7.0-r0 None possibly vulnerable
mbedtls 3.21-main 2.6.0-r0 None possibly vulnerable
mbedtls 3.21-main 2.4.2-r0 None possibly vulnerable
mbedtls 3.21-main 2.28.8-r0 None possibly vulnerable
mbedtls 3.21-main 2.28.7-r0 None possibly vulnerable
mbedtls 3.21-main 2.28.5-r0 None possibly vulnerable
mbedtls 3.21-main 2.28.1-r0 None possibly vulnerable
mbedtls 3.21-main 2.16.8-r0 None possibly vulnerable
mbedtls 3.21-main 2.16.6-r0 None possibly vulnerable
mbedtls 3.21-main 2.16.4-r0 None possibly vulnerable
mbedtls 3.21-main 2.16.3-r0 None possibly vulnerable
mbedtls 3.21-main 2.16.12-r0 None possibly vulnerable
mbedtls 3.21-main 2.14.1-r0 None possibly vulnerable
mbedtls 3.21-main 2.12.0-r0 None possibly vulnerable
mbedtls 3.20-main 3.6.4-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
mbedtls 3.20-main 3.6.3-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mbedtls 3.20-main 3.6.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mbedtls 3.20-main 3.6.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mbedtls 3.20-main 2.7.0-r0 None possibly vulnerable
mbedtls 3.20-main 2.6.0-r0 None possibly vulnerable
mbedtls 3.20-main 2.4.2-r0 None possibly vulnerable
mbedtls 3.20-main 2.28.8-r0 None possibly vulnerable
mbedtls 3.20-main 2.28.7-r0 None possibly vulnerable
mbedtls 3.20-main 2.28.5-r0 None possibly vulnerable
mbedtls 3.20-main 2.28.1-r0 None possibly vulnerable
mbedtls 3.20-main 2.16.8-r0 None possibly vulnerable
mbedtls 3.20-main 2.16.6-r0 None possibly vulnerable
mbedtls 3.20-main 2.16.4-r0 None possibly vulnerable
mbedtls 3.20-main 2.16.3-r0 None possibly vulnerable
mbedtls 3.20-main 2.16.12-r0 None possibly vulnerable
mbedtls 3.20-main 2.14.1-r0 None possibly vulnerable
mbedtls 3.20-main 2.12.0-r0 None possibly vulnerable
mbedtls 3.19-main 2.7.0-r0 None possibly vulnerable
mbedtls 3.19-main 2.6.0-r0 None possibly vulnerable
mbedtls 3.19-main 2.4.2-r0 None possibly vulnerable
mbedtls 3.19-main 2.28.9-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mbedtls 3.19-main 2.28.8-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mbedtls 3.19-main 2.28.7-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mbedtls 3.19-main 2.28.5-r0 None possibly vulnerable
mbedtls 3.19-main 2.28.10-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mbedtls 3.19-main 2.28.1-r0 None possibly vulnerable
mbedtls 3.19-main 2.16.8-r0 None possibly vulnerable
mbedtls 3.19-main 2.16.6-r0 None possibly vulnerable
mbedtls 3.19-main 2.16.4-r0 None possibly vulnerable
mbedtls 3.19-main 2.16.3-r0 None possibly vulnerable
mbedtls 3.19-main 2.16.12-r0 None possibly vulnerable
mbedtls 3.19-main 2.14.1-r0 None possibly vulnerable
mbedtls 3.19-main 2.12.0-r0 None possibly vulnerable