Home

Description

EVerest is an EV charging software stack. Prior to version 2025.10.0, once the module receives a SDP request, it creates a whole new set of objects like `Session`, `IConnection` which open new TCP socket for the ISO15118-20 communications and registers callbacks for the created file descriptor, without closing and destroying the previous ones. Previous `Session` is not saved and the usage of an `unique_ptr` is lost, destroying connection data. Latter, if the used socket and therefore file descriptor is not the last one, it will lead to a null pointer dereference. Version 2025.10.0 fixes the issue.

PUBLISHED Reserved 2025-12-15 | Published 2026-01-21 | Updated 2026-01-21 | Assigner GitHub_M




HIGH: 7.4CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Problem types

CWE-770: Allocation of Resources Without Limits or Throttling

Product status

< 2025.10.0
affected

References

github.com/...t-core/security/advisories/GHSA-4h8h-x5cp-g22r

cve.org (CVE-2025-68136)

nvd.nist.gov (CVE-2025-68136)

Download JSON