CVE-2025-65495 is an integer signedness error in the tls_verify_call_back() function of OISM libcoap 4.3.5. This vulnerability allows remote attackers to trigger a denial of service by providing a specially crafted TLS certificate, leading to a negative value being misinterpreted as a memory allocation size. With a CVSS score of 7.5 (HIGH), this vulnerability can be exploited remotely with low complexity and no user interaction, resulting in a complete loss of availability. Currently, there is no public exploit code available, and the vulnerability has not been observed in active exploitation, nor has it garnered significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.3.5CPE matchmatch criteria | cpe:2.3:a:libcoap:libcoap:4.3.5:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.