A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model command processing logic. When an InvokeCommandRequest is sent to a nonexistent endpoint and cluster (e.g., 0x34), the code incorrectly treats the endpoint as valid due to missing checks in CodegenDataModelProvider::Invoke. This causes a VerifyOrDie failure in ProcessCommandDataIB and results in a crash (SIGABRT). The issue has been acknowledged and fixed in a later revision (PR #37207).
Metrics
Affected Vendors & Products
References
History
Wed, 29 Jul 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Matter SDK Assertion Crash on Nonexistent Endpoint | |
| Weaknesses | CWE-20 CWE-742 |
Sat, 25 Jul 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Reachable Assertion in Matter SDK Command Processing Leading to Crash |
Wed, 22 Jul 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Reachable Assertion in Matter SDK Command Processing Leading to Crash | |
| Weaknesses | CWE-20 CWE-742 |
Fri, 17 Jul 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Matter SDK Crash via Unchecked Endpoint in InvokeCommandRequest | |
| Weaknesses | CWE-682 |
Thu, 16 Jul 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Matter SDK Crash via Unchecked Endpoint in InvokeCommandRequest | |
| Weaknesses | CWE-682 |
Tue, 14 Jul 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model command processing logic. When an InvokeCommandRequest is sent to a nonexistent endpoint and cluster (e.g., 0x34), the code incorrectly treats the endpoint as valid due to missing checks in CodegenDataModelProvider::Invoke. This causes a VerifyOrDie failure in ProcessCommandDataIB and results in a crash (SIGABRT). The issue has been acknowledged and fixed in a later revision (PR #37207). | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-07-14T00:00:00.000Z
Updated: 2026-07-15T14:17:52.828Z
Reserved: 2025-08-16T00:00:00.000Z
Link: CVE-2025-56365
No data.
No data.
No data.