Null Pointer Dereference Vulnerability in Matter SDK by Connectivity Standards Alliance
CVE-2025-56363

7.5HIGH

What is CVE-2025-56363?

A null pointer dereference vulnerability has been identified in the Matter SDK, specifically within the ReadRevisionAttribute function utilized across various clusters, including Channel, Account Login, and TargetNavigator. This vulnerability arises due to inadequate validation of the delegate pointer before it is dereferenced. A potential attacker could exploit this flaw by sending a specially crafted read request to the affected device, resulting in a denial of service and causing the device to crash. The issue has been validated in SDK versions prior to 1.4.0, emphasizing the need for prompt updates and mitigations for affected users and developers.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.