CVE 5.1 MEDIUM

Wazuh NULL pointer dereference in fim_alert line 666_CVE-2025-64169

5.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Description

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 3.7.0 to before 4.12.0, fim_alert() implementation does not check whether oldsum->md5 is NULL or not before dereferencing it. A compromised agent can cause a crash of analysisd by sending a specially crafted message to the wazuh manager. This issue has been patched in version 4.12.0.

Basic Information

ID CVE-2025-64169
Source GitHub_M
Published Nov 21, 2025 at 18:39
Modified Nov 21, 2025 at 19:05

Affected Product

Vendor wazuh
Product wazuh
Version >= 3.7.0, < 4.12.0
Affected Versions wazuh wazuh >= 3.7.0, < 4.12.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.