A use of uninitialized value vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, where the `GetDestinationGroupId().Value()` method is called without first checking whether a value exists. This leads to a crash when an InvokeCommand is sent without initializing the destination group ID. The issue affects all versions before commit 0360cc3 (Dec 5, 2024) and leads to denial of service through SIGABRT. It is fixed by adding a .HasValue() check before access.
Metrics
Affected Vendors & Products
References
History
Mon, 03 Aug 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Matter SDK Uninitialized Value Crash in GetDestinationGroupId | |
| Weaknesses | CWE-457 |
Fri, 31 Jul 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Matter SDK Use of Uninitialized Value Leads to Denial of Service | |
| Weaknesses | CWE-457 |
Sun, 26 Jul 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Matter SDK Use of Uninitialized Value Leads to Denial of Service | |
| Weaknesses | CWE-457 |
Fri, 17 Jul 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Matter SDK Uninitialized Value Causing Crash on InvokeCommand | |
| Weaknesses | CWE-457 |
Thu, 16 Jul 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Matter SDK Uninitialized Value Causing Crash on InvokeCommand | |
| Weaknesses | CWE-457 |
Tue, 14 Jul 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A use of uninitialized value vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, where the `GetDestinationGroupId().Value()` method is called without first checking whether a value exists. This leads to a crash when an InvokeCommand is sent without initializing the destination group ID. The issue affects all versions before commit 0360cc3 (Dec 5, 2024) and leads to denial of service through SIGABRT. It is fixed by adding a .HasValue() check before access. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-07-14T00:00:00.000Z
Updated: 2026-07-15T14:20:03.829Z
Reserved: 2025-08-16T00:00:00.000Z
Link: CVE-2025-56364
No data.
No data.
No data.