Executive brief
A denial-of-service vulnerability exists in the Matter SDK, a widely used open-source standard for smart home device compatibility. By sending a specific command to a non-existent component on a smart device, an attacker can cause the device's software to crash. This could lead to temporary loss of control over smart home appliances or security systems until the device is manually restarted.
Technical details
A reachable assertion vulnerability exists in the Matter SDK's interaction model command processing logic. The root cause is a lack of endpoint validation in CodegenDataModelProvider::Invoke, which incorrectly treats non-existent endpoints as valid when certain interfaces (like SoftwareDiagnostics) are registered as wildcard endpoints. When an InvokeCommandRequest is sent to an invalid endpoint/cluster combination, it triggers a VerifyOrDie failure in ProcessCommandDataIB, resulting in a SIGABRT crash. This issue is fixed in version 1.4.0 and later via PR #37207.
Affected products
- Project CHIP Matter SDK (connectedhomeip) before 1.4.0
Timeline
- 2025-01-27: disclosed: Issue reported and fix proposed in PR #37207
- 2025-01-31: patched: Fix merged into master branch
- 2026-07-14: advisory: CVE published to NVD