From 44d047d496df891128d9e2648bf035381db8bd32 Mon Sep 17 00:00:00 2001 From: Jeremy Newton Date: Fri, 31 Oct 2025 22:11:52 -0400 Subject: [PATCH] mbedtls: CVE-2025-48965 fix Backported from 3.6.x Prevents a NULL pointer deference due to an unset variable --- Externals/mbedtls/library/asn1write.c | 1 + 1 file changed, 1 insertion(+) diff --git a/Externals/mbedtls/library/asn1write.c b/Externals/mbedtls/library/asn1write.c index 0147c49f68..c671bdd9ed 100644 --- a/Externals/mbedtls/library/asn1write.c +++ b/Externals/mbedtls/library/asn1write.c @@ -453,6 +453,7 @@ mbedtls_asn1_named_data *mbedtls_asn1_store_named_data( } else if (val_len == 0) { mbedtls_free(cur->val.p); cur->val.p = NULL; + cur->val.len = 0; } else if (cur->val.len != val_len) { /* * Enlarge existing value buffer if needed