A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model command processing logic. When an InvokeCommandRequest is sent to a nonexistent endpoint and cluster (e.g., 0x34), the code incorrectly treats the endpoint as valid due to missing checks in CodegenDataModelProvider::Invoke. This causes a VerifyOrDie failure in ProcessCommandDataIB and results in a crash (SIGABRT). The issue has been acknowledged and fixed in a later revision (PR #37207).
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 22 Jul 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Reachable Assertion in Matter SDK Command Processing Leading to Crash | |
| Weaknesses | CWE-20 CWE-742 |
Fri, 17 Jul 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Matter SDK Crash via Unchecked Endpoint in InvokeCommandRequest | |
| Weaknesses | CWE-682 |
Thu, 16 Jul 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Matter SDK Crash via Unchecked Endpoint in InvokeCommandRequest | |
| Weaknesses | CWE-682 |
Tue, 14 Jul 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model command processing logic. When an InvokeCommandRequest is sent to a nonexistent endpoint and cluster (e.g., 0x34), the code incorrectly treats the endpoint as valid due to missing checks in CodegenDataModelProvider::Invoke. This causes a VerifyOrDie failure in ProcessCommandDataIB and results in a crash (SIGABRT). The issue has been acknowledged and fixed in a later revision (PR #37207). | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-07-15T14:17:52.828Z
Reserved: 2025-08-16T00:00:00.000Z
Link: CVE-2025-56365
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-22T10:15:02Z