Skip to main content

Security update for mbedtls-2

0
Medium
Published: 06/22/2026 (06/22/2026, 13:08:31 UTC)
Source: GCVE Database
Vendor/Project: SUSE Product Security Team
Product: SUSE

Description

This update for mbedtls-2 fixes the following issues: Changes in mbedtls-2: - Enable SRTP and DTLS protocols needed by some software. - Update to version 2.28.10: Default behavior changes * In TLS clients, if mbedtls_ssl_set_hostname() has not been called, mbedtls_ssl_handshake() now fails with MBEDTLS_ERR_SSL_CERTIFICATE_VERIFICATION_WITHOUT_HOSTNAME if certificate-based authentication of the server is attempted. This is because authenticating a server without knowing what name to expect is usually insecure. To restore the old behavior, either call mbedtls_ssl_set_hostname() with NULL as the hostname, or enable the new compile-time option MBEDTLS_SSL_CLI_ALLOW_WEAK_CERTIFICATE_VERIFICATION_WITHOUT_HOSTNAME. The content of ssl->hostname after mbedtls_ssl_set_hostname(ssl, NULL) has changed, see the documentation of the hostname field in the mbedtls_ssl_context struct type for details. Security * Note that TLS clients should generally call mbedtls_ssl_set_hostname() if they use certificate authentication (i.e. not pre-shared keys). Otherwise, in many scenarios, the server could be impersonated. The library will now prevent the handshake and return MBEDTLS_ERR_SSL_CERTIFICATE_VERIFICATION_WITHOUT_HOSTNAME if mbedtls_ssl_set_hostname() has not been called. CVE-2025-27809 (boo#1240051) * Zeroize temporary heap buffers used in PSA operations. * Fix a vulnerability in the TLS 1.2 handshake. If memory allocation failed or there was a cryptographic hardware failure when calculating the Finished message, it could be calculated incorrectly. This would break the security guarantees of the TLS handshake. CVE-2025-27810 (boo#1240052) Bugfix * Use 'mbedtls_net_close' instead of 'close' in 'mbedtls_net_bind' and 'mbedtls_net_connect' to prevent possible double close fd problems. Fixes gh#Mbed-TLS/mbedtls#9711. * Fix compilation on MS-DOS DJGPP. Fixes gh#Mbed-TLS/mbedtls#9813. * Fix missing constraints on the AES-NI inline assembly which is used on GCC-like compilers when building AES for generic x86_64 targets. This may have resulted in incorrect code with some compilers, depending on optimizations. Fixes gh#Mbed-TLS/mbedtls#9819. * Fix issue where psa_key_derivation_input_integer() is not detecting bad state after an operation has been aborted. * Fix definition of MBEDTLS_PRINTF_SIZET to prevent runtime crashes that occurred whenever SSL debugging was enabled on a copy of Mbed TLS built with Visual Studio 2013 or MinGW. Fixes gh#Mbed-TLS/mbedtls#10017. * Remove Everest Visual Studio 2010 compatibility headers, which could shadow standard CRT headers inttypes.h and stdbool.h with incomplete implementatios if placed on the include path, eg. when building Mbed TLS with the .sln file shipped with the project.

Affected software

Affected versions
SUSEaarch64libmbedcrypto7-2.28.10-bp160.1.1.aarch64libmbedtls14-2.28.10-bp160.1.1.aarch64libmbedx509-1-2.28.10-bp160.1.1.aarch64

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
SUSE Product Security Team
Advisory Id
openSUSE-SU-2026:21145-1
Cve Count
3
Additional Cves
["CVE-2025-27809","CVE-2025-27810"]

Threat ID: 6aab497555bf5e2cf5990e27

Added to database: 09/17/2026, 01:59:17 UTC

Last updated: 09/17/2026, 02:02:24 UTC

Views: 1

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses