Skip to main content

Security update for mbedtls

0
Critical
Published: 06/22/2026 (06/22/2026, 13:34:13 UTC)
Source: GCVE Database
Vendor/Project: SUSE Product Security Team
Product: SUSE

Description

This security update for mbedtls addresses multiple critical vulnerabilities fixed in version 3.6.6, including buffer underrun, certificate verification flaws, authentication bypass, memory management errors, timing side channels, race conditions, and RNG state duplication issues. These vulnerabilities affect cryptographic operations and could lead to key extraction, signature bypass, downgrade attacks, and other serious security impacts.

Affected software

Affected versions
SUSEaarch64libeverest-3.6.6-bp160.1.1.aarch64libmbedcrypto16-3.6.6-bp160.1.1.aarch64libmbedtls21-3.6.6-bp160.1.1.aarch64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/17/2026, 02:17:05 UTC

Technical Analysis

The mbedtls update to version 3.6.6 (LTS maintenance update from 3.6.1) fixes several security issues discovered across versions 3.6.2 to 3.6.6. Notable vulnerabilities include CVE-2024-49195 (buffer underrun in pkwrite), CVE-2025-27809 (certificate verification accepting arbitrary hostnames), CVE-2025-27810 (possible authentication bypass on failed memory allocation or hardware errors), timing side channels in PKCS#7 padding removal and RSA operations, race conditions in AES-NI support detection leading to key extraction or forgery, padding-oracle attacks, and RNG state duplication across process forks and VM cloning. These flaws impact cryptographic integrity, authentication, and confidentiality.

Potential Impact

Exploitation of these vulnerabilities could allow attackers to bypass authentication, perform man-in-the-middle downgrade attacks, extract cryptographic keys, cause signature verification bypass, trigger memory corruption, and exploit timing side channels to leak sensitive information. The issues affect core cryptographic functions and could compromise secure communications and data protection relying on mbedtls.

Mitigation Recommendations

A security update to mbedtls version 3.6.6 is available that addresses all listed vulnerabilities. Users and administrators should upgrade to this version promptly to mitigate these critical security risks. No additional vendor advisory information is provided, so patch status beyond this update is not confirmed.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
SUSE Product Security Team
Advisory Id
openSUSE-SU-2026:21144-1
Cve Count
15
Additional Cves
["CVE-2025-27809","CVE-2025-27810","CVE-2025-47917","CVE-2025-48965","CVE-2025-49087","CVE-2025-49600","CVE-2025-49601","CVE-2025-52496","CVE-2025-52497","CVE-2025-54764","CVE-2025-59438","CVE-2026-25833","CVE-2026-25834","CVE-2026-25835"]
State
PUBLISHED

Threat ID: 6aab497555bf5e2cf5990e28

Added to database: 09/17/2026, 01:59:17 UTC

Last enriched: 09/17/2026, 02:17:05 UTC

Last updated: 09/17/2026, 02:17:05 UTC

Views: 1

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses