UBUNTU-CVE-2025-54764
Dashboard / Vulnerabilities / UBUNTU-CVE-2025-54764
Summary:
Details: Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_inv or mbedtls_mpi_gcd.
References: https://ubuntu.com/security/CVE-2025-54764, https://www.cve.org/CVERecord?id=CVE-2025-54764, https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2025-10-ssbleed-mstep/, https://mbed-tls.readthedocs.io/en/latest/tech-updates/security-advisories/, https://github.com/Mbed-TLS/mbedtls/compare/8f4779c6fa40374f88404787bebad85cc7e9969b..eb346801263ba4612b5e29633bd55fe18943ca65, https://github.com/Mbed-TLS/mbedtls/compare/9b54f934588bc373f3c3f5d45b5a3ad0ae003082..99270322ffac3546f813b1069fd6efb667cdce3f, https://github.com/Mbed-TLS/mbedtls/compare/246d86b941ef2d2bdeabd7035efe7200bc609b91..a08faf90700e46f6aa2a6e3fee8a6a71ddb816ce, https://github.com/Mbed-TLS/mbedtls/compare/246d86b941ef2d2bdeabd7035efe7200bc609b91..30f073236922fe4e528fdf82eb442babb50516fa
Affected packages
Package
Name: mbedtls
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
