Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-52496

Опубликовано: 04 июл. 2025
Источник: debian
EPSS Низкий

Описание

Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may be able to extract an AES key from a multithreaded program, or perform a GCM forgery.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mbedtlsfixed3.6.4-1package

Примечания

  • https://github.com/Mbed-TLS/mbedtls-docs/blob/main/security-advisories/mbedtls-security-advisory-2025-06-1.md

EPSS

Процентиль: 4%
0.0002
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
7 месяцев назад

Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may be able to extract an AES key from a multithreaded program, or perform a GCM forgery.

CVSS3: 7.8
nvd
7 месяцев назад

Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may be able to extract an AES key from a multithreaded program, or perform a GCM forgery.

msrc
5 месяцев назад

Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may be able to extract an AES key from a multithreaded program, or perform a GCM forgery.

CVSS3: 7.8
github
7 месяцев назад

Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may be able to extract an AES key from a multithreaded program, or perform a GCM forgery.

CVSS3: 7.8
fstec
7 месяцев назад

Уязвимость функции mbedtls_aesni_has_support() программного обеспечения Mbed TLS, позволяющая нарушителю оказать воздействие на целостность и конфиденциальность защищаемой информации

EPSS

Процентиль: 4%
0.0002
Низкий