A null pointer dereference vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, affecting the ReadRevisionAttribute function used in multiple clusters (Channel, Account Login, TargetNavigator, etc.). The function lacks proper validation of the delegate pointer before dereferencing. A remote unauthenticated attacker can exploit this issue by sending a crafted read request, causing the device to crash (denial of service). This issue has been confirmed in SDK version v1.4 (commit ab3d5ae).
History

Fri, 31 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference in Matter SDK ReadRevision Attribute (Denial of Service)

Wed, 29 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference in Matter SDK ReadRevisionAttribute causing Device Crash

Sat, 25 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference in Matter SDK ReadRevisionAttribute causing Device Crash

Wed, 22 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via Null‑Pointer Dereference in Matter SDK ReadRevisionAttribute

Fri, 17 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via Null‑Pointer Dereference in Matter SDK ReadRevisionAttribute

Thu, 16 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Description A null pointer dereference vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, affecting the ReadRevisionAttribute function used in multiple clusters (Channel, Account Login, TargetNavigator, etc.). The function lacks proper validation of the delegate pointer before dereferencing. A remote unauthenticated attacker can exploit this issue by sending a crafted read request, causing the device to crash (denial of service). This issue has been confirmed in SDK version v1.4 (commit ab3d5ae).
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2026-07-14T00:00:00.000Z

Updated: 2026-07-15T14:21:50.878Z

Reserved: 2025-08-16T00:00:00.000Z

Link: CVE-2025-56363

cve-icon Vulnrichment

Updated: 2026-07-15T14:21:35.273Z

cve-icon NVD

No data.

cve-icon Redhat

No data.