NULL pointer dereference in coapdtlsgeneratecookie() in src/coapopenssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSLgetSSL_CTX() to return NULL.
{ "binaries": [ { "binary_version": "4.1.2-1", "binary_name": "libcoap-1-0" }, { "binary_version": "4.1.2-1", "binary_name": "libcoap-1-0-bin" }, { "binary_version": "4.1.2-1", "binary_name": "libcoap-1-0-dev" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-65496.json"
{ "binaries": [ { "binary_version": "4.2.1-1", "binary_name": "libcoap2" }, { "binary_version": "4.2.1-1", "binary_name": "libcoap2-bin" }, { "binary_version": "4.2.1-1", "binary_name": "libcoap2-dev" } ] }
{ "binaries": [ { "binary_version": "4.2.1-1build1", "binary_name": "libcoap2" }, { "binary_version": "4.2.1-1build1", "binary_name": "libcoap2-bin" }, { "binary_version": "4.2.1-1build1", "binary_name": "libcoap2-dev" } ] }
{ "binaries": [ { "binary_version": "4.3.0-2build1", "binary_name": "libcoap3" }, { "binary_version": "4.3.0-2build1", "binary_name": "libcoap3-bin" }, { "binary_version": "4.3.0-2build1", "binary_name": "libcoap3-dev" } ] }
{ "binaries": [ { "binary_version": "4.3.4-1.1build4", "binary_name": "libcoap3-bin" }, { "binary_version": "4.3.4-1.1build4", "binary_name": "libcoap3-dev" }, { "binary_version": "4.3.4-1.1build4", "binary_name": "libcoap3t64" } ] }