A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model command processing logic. When an InvokeCommandRequest is sent to a nonexistent endpoint and cluster (e.g., 0x34), the code incorrectly treats the endpoint as valid due to missing checks in CodegenDataModelProvider::Invoke. This causes a VerifyOrDie failure in ProcessCommandDataIB and results in a crash (SIGABRT). The issue has been acknowledged and fixed in a later revision (PR #37207).
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/56xxx/CVE-2025-56365.json",
"cna_assigner": "mitre"
}{
"cpe": "cpe:2.3:a:csa-iot:matter:*:*:*:*:*:*:*:*",
"source": [
"DESCRIPTION",
"CPE_RANGE"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.4.0"
},
{
"fixed": "1.4.0.0"
}
]
}[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"10914484396529890614862958618586276642",
"15556846030561399203845313242997755120",
"132238975706345797081838961486091633436",
"162092063713916714010188393539688103404",
"110727327429346046373395458059548612709"
]
},
"signature_version": "v1",
"source": "https://github.com/project-chip/connectedhomeip/commit/43aa98c2d30ee547c6b587b9de7bbb794f175ece",
"signature_type": "Line",
"target": {
"file": "src/platform/ESP32/ConfigurationManagerImpl.cpp"
},
"id": "CVE-2025-56365-4d1af1f5",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"262590375615370306282283240500013164873",
"306492425597676737952160135003560418922",
"210056201948984650332561026685601642323",
"188959626759016752050347294467993822603",
"54959768588438366669785620345793695150",
"100354885865924945642862212764553257232",
"88988577723611573100389811662833451155"
]
},
"signature_version": "v1",
"source": "https://github.com/project-chip/connectedhomeip/commit/43aa98c2d30ee547c6b587b9de7bbb794f175ece",
"signature_type": "Line",
"target": {
"file": "src/platform/ESP32/nimble/BLEManagerImpl.cpp"
},
"id": "CVE-2025-56365-63bbf9b9",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"254065092782683959562106826029491668853",
"157303372587191355698707652722272234492",
"73855282504442410241031297073166812724",
"308787766795530858984041756622439387598",
"240199258269686967681970961699231535059",
"224601829990959705522627067047702248248",
"128206547482550248812265397428866108613",
"304038845803326732028424872839848327314",
"90065420893942170477090140449533964720",
"177255599875748510116158569938485068028",
"60074632605672314165726005829549386078",
"291076950096347207641768712205229333886",
"108071126571248915821445459341842497449",
"132296518656652197495350330570392493140"
]
},
"signature_version": "v1",
"source": "https://github.com/project-chip/connectedhomeip/commit/43aa98c2d30ee547c6b587b9de7bbb794f175ece",
"signature_type": "Line",
"target": {
"file": "examples/platform/esp32/common/Esp32AppServer.cpp"
},
"id": "CVE-2025-56365-651e4ca7",
"deprecated": false
}
]
"2026-07-22T04:18:33Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-56365.json"