Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-59438

Опубликовано: 21 окт. 2025
Источник: debian

Описание

Mbed TLS through 3.6.4 has an Observable Timing Discrepancy.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mbedtlsfixed3.6.5-0.1package
mbedtlsfixed3.6.5-0.1~deb13u1trixiepackage

Примечания

  • https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2025-10-invalid-padding-error/

  • https://github.com/Mbed-TLS/mbedtls/commit/155de2ab775e77ab6fa81bf2b1e6e63768123bc1 (mbedtls-3.6.5)

  • https://github.com/Mbed-TLS/mbedtls/commit/d179dc80a5b13189c79fe4531eacb28698a7a0e9 (mbedtls-3.6.5)

  • https://github.com/Mbed-TLS/mbedtls/commit/e74b42832e4af11606ef8aae2c9404b4acaa2c6d (mbedtls-3.6.5)

  • https://github.com/Mbed-TLS/mbedtls/commit/3b380daedbce9fae3e7ed7e84f18e97876e7e6f3 (mbedtls-3.6.5)

  • https://github.com/Mbed-TLS/mbedtls/commit/04dfd704325a6dbc2a13eb7f418eaca9ae9ca549 (mbedtls-3.6.5)

Связанные уязвимости

CVSS3: 5.3
ubuntu
4 месяца назад

Mbed TLS through 3.6.4 has an Observable Timing Discrepancy.

CVSS3: 5.3
nvd
4 месяца назад

Mbed TLS through 3.6.4 has an Observable Timing Discrepancy.

suse-cvrf
3 месяца назад

Security update for micropython

CVSS3: 5.3
github
4 месяца назад

Mbed TLS through 3.6.4 has an Observable Timing Discrepancy.