CVE-2025-56365

Source
https://cve.org/CVERecord?id=CVE-2025-56365
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-56365.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-56365
Published
2026-07-14T00:00:00Z
Modified
2026-07-22T04:18:33.390217Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model command processing logic. When an InvokeCommandRequest is sent to a nonexistent endpoint and cluster (e.g., 0x34), the code incorrectly treats the endpoint as valid due to missing checks in CodegenDataModelProvider::Invoke. This causes a VerifyOrDie failure in ProcessCommandDataIB and results in a crash (SIGABRT). The issue has been acknowledged and fixed in a later revision (PR #37207).

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/56xxx/CVE-2025-56365.json",
    "cna_assigner": "mitre"
}
References

Affected packages

Git / github.com/project-chip/connectedhomeip

Affected ranges

Type
GIT
Repo
https://github.com/project-chip/connectedhomeip
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:csa-iot:matter:*:*:*:*:*:*:*:*",
    "source": [
        "DESCRIPTION",
        "CPE_RANGE"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.4.0"
        },
        {
            "fixed": "1.4.0.0"
        }
    ]
}

Affected versions

Other
SVE_23_03/rc1
SVE_23_03/rc2
SVE_23_09/rc1
TE8/rc1
TE8/rc2
TE8/rc3
TE9
TE_23_02/rc1
TE_23_02/rc2
TE_24_01/rc1
test_event_1_2012_03_05
test_event_2_2012_04_19
test_event_2_2012_04_21
test_event_2_2012_04_22
test_event_3_2012_04_21
test_event_3_2021_06_01
test_event_3_2021_06_03
test_event_4_2021_07_06
v2021_01_27-alpha
v2021_02_02-alpha
v2021_02_10-alpha
TH-Matter-1.*
TH-Matter-1.2
V1.*
V1.0.0.1
v1.*
v1.0.0.2
v1.1.0.0
v1.1.0.1
v1.2.0.0
v1.2.0.1
v1.3.0.0

Database specific

vanir_signatures
[
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "10914484396529890614862958618586276642",
                "15556846030561399203845313242997755120",
                "132238975706345797081838961486091633436",
                "162092063713916714010188393539688103404",
                "110727327429346046373395458059548612709"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/project-chip/connectedhomeip/commit/43aa98c2d30ee547c6b587b9de7bbb794f175ece",
        "signature_type": "Line",
        "target": {
            "file": "src/platform/ESP32/ConfigurationManagerImpl.cpp"
        },
        "id": "CVE-2025-56365-4d1af1f5",
        "deprecated": false
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "262590375615370306282283240500013164873",
                "306492425597676737952160135003560418922",
                "210056201948984650332561026685601642323",
                "188959626759016752050347294467993822603",
                "54959768588438366669785620345793695150",
                "100354885865924945642862212764553257232",
                "88988577723611573100389811662833451155"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/project-chip/connectedhomeip/commit/43aa98c2d30ee547c6b587b9de7bbb794f175ece",
        "signature_type": "Line",
        "target": {
            "file": "src/platform/ESP32/nimble/BLEManagerImpl.cpp"
        },
        "id": "CVE-2025-56365-63bbf9b9",
        "deprecated": false
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "254065092782683959562106826029491668853",
                "157303372587191355698707652722272234492",
                "73855282504442410241031297073166812724",
                "308787766795530858984041756622439387598",
                "240199258269686967681970961699231535059",
                "224601829990959705522627067047702248248",
                "128206547482550248812265397428866108613",
                "304038845803326732028424872839848327314",
                "90065420893942170477090140449533964720",
                "177255599875748510116158569938485068028",
                "60074632605672314165726005829549386078",
                "291076950096347207641768712205229333886",
                "108071126571248915821445459341842497449",
                "132296518656652197495350330570392493140"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/project-chip/connectedhomeip/commit/43aa98c2d30ee547c6b587b9de7bbb794f175ece",
        "signature_type": "Line",
        "target": {
            "file": "examples/platform/esp32/common/Esp32AppServer.cpp"
        },
        "id": "CVE-2025-56365-651e4ca7",
        "deprecated": false
    }
]
vanir_signatures_modified
"2026-07-22T04:18:33Z"
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-56365.json"