PT-2025-48528 · Julia · Mbedtls Jll

Published

2025-11-21

·

Updated

2025-11-21

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls asn1 store named data can trigger conflicting data with val.p of NULL but val.len greater than zero.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

JLSEC-2025-230

Affected Products

Mbedtls Jll