Описание
Security update for mbedtls
This update for mbedtls fixes the following issues:
Changes in mbedtls:
- Update to version 3.6.7:
- CVE-2026-25832: TLS 1.3 client accepted HRR selecting unadvertised group (boo#1280186)
- Fix TLS 1.3 clients to reject a HelloRetryRequest whose selected group was not advertised in the original ClientHello
Список пакетов
openSUSE Leap 16.0
libeverest-3.6.7-bp160.1.1
libeverest-x86-64-v3-3.6.7-bp160.1.1
libmbedcrypto16-3.6.7-bp160.1.1
libmbedcrypto16-x86-64-v3-3.6.7-bp160.1.1
libmbedtls21-3.6.7-bp160.1.1
libmbedtls21-x86-64-v3-3.6.7-bp160.1.1
libmbedx509-7-3.6.7-bp160.1.1
libmbedx509-7-x86-64-v3-3.6.7-bp160.1.1
libp256m-3.6.7-bp160.1.1
libp256m-x86-64-v3-3.6.7-bp160.1.1
mbedtls-devel-3.6.7-bp160.1.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1280186
- SUSE CVE CVE-2026-25832 page
Описание
In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.
Затронутые продукты
openSUSE Leap 16.0:libeverest-3.6.7-bp160.1.1
openSUSE Leap 16.0:libeverest-x86-64-v3-3.6.7-bp160.1.1
openSUSE Leap 16.0:libmbedcrypto16-3.6.7-bp160.1.1
openSUSE Leap 16.0:libmbedcrypto16-x86-64-v3-3.6.7-bp160.1.1
Ссылки
- CVE-2026-25832
- SUSE Bug 1280186