Описание
Security update for mbedtls-2
This update for mbedtls-2 fixes the following issues:
Changes in mbedtls-2:
- CVE-2025-52496: race condition in AESNI support detection, AES key disclosure / GCM forgery in multithreaded programs (boo#1245810)
- CVE-2025-59438: padding oracle through timing of cipher error reporting (boo#1252454)
Список пакетов
openSUSE Leap 16.0
libmbedcrypto7-2.28.10-bp160.2.1
libmbedcrypto7-x86-64-v3-2.28.10-bp160.2.1
libmbedtls14-2.28.10-bp160.2.1
libmbedtls14-x86-64-v3-2.28.10-bp160.2.1
libmbedx509-1-2.28.10-bp160.2.1
libmbedx509-1-x86-64-v3-2.28.10-bp160.2.1
mbedtls-2-devel-2.28.10-bp160.2.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1245810
- SUSE Bug 1252454
- SUSE CVE CVE-2025-52496 page
- SUSE CVE CVE-2025-59438 page
Описание
Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may be able to extract an AES key from a multithreaded program, or perform a GCM forgery.
Затронутые продукты
openSUSE Leap 16.0:libmbedcrypto7-2.28.10-bp160.2.1
openSUSE Leap 16.0:libmbedcrypto7-x86-64-v3-2.28.10-bp160.2.1
openSUSE Leap 16.0:libmbedtls14-2.28.10-bp160.2.1
openSUSE Leap 16.0:libmbedtls14-x86-64-v3-2.28.10-bp160.2.1
Ссылки
- CVE-2025-52496
- SUSE Bug 1245810
Описание
Mbed TLS through 3.6.4 has an Observable Timing Discrepancy.
Затронутые продукты
openSUSE Leap 16.0:libmbedcrypto7-2.28.10-bp160.2.1
openSUSE Leap 16.0:libmbedcrypto7-x86-64-v3-2.28.10-bp160.2.1
openSUSE Leap 16.0:libmbedtls14-2.28.10-bp160.2.1
openSUSE Leap 16.0:libmbedtls14-x86-64-v3-2.28.10-bp160.2.1
Ссылки
- CVE-2025-59438
- SUSE Bug 1252433