openSUSE-SU-2026:21144-1

    Dashboard / Vulnerabilities / openSUSE-SU-2026:21144-1

    openSUSE-SU-2026:21144-1

    Published: 22 Jun 2026Last Modified: 30 Jun 2026

    Summary: Security update for mbedtls

    Details: This update for mbedtls fixes the following issues: Changes in mbedtls: - Update to 3.6.6 (LTS maintenance update from 3.6.1); security fixes accumulated across the 3.6.2-3.6.6 releases: * CVE-2024-49195 (boo#1231708): buffer underrun in pkwrite when writing an opaque key pair * CVE-2025-27809 (boo#1240051): certificate verification accepted arbitrary hostnames * CVE-2025-27810 (boo#1240052): possible authentication bypass on failed memory allocation / hardware errors * CVE-2025-47917 (boo#1246783): misleading memory management in mbedtls_x509_string_to_names() * CVE-2025-48965 (boo#1246784): NULL pointer dereference after mbedtls_asn1_store_named_data() * CVE-2025-49087 (boo#1246973): timing side channel in PKCS#7 padding removal * CVE-2025-49600 (boo#1245808): unchecked return values in LMS verification allow signature bypass via fault injection * CVE-2025-49601 (boo#1245809): out-of-bounds read in mbedtls_lms_import_public_key() * CVE-2025-52496 (boo#1245810): race in AES-NI support detection can lead to AES key extraction or GCM forgery * CVE-2025-52497 (boo#1245811): one-byte heap underflow when parsing PEM-encrypted material * CVE-2025-54764 (boo#1252341): timing attacks in RSA operations * CVE-2025-59438 (boo#1252454): padding-oracle attack via timing of cipher error reporting * CVE-2026-25833: PSA RNG state duplicated across fork() * CVE-2026-25834: TLS 1.3 HelloRetryRequest man-in-the-middle session-resumption downgrade * CVE-2026-25835: RNG state duplicated when application/VM state is cloned

    Affected packages

    Package

    Name: mbedtls

    Purl: pkg:rpm/opensuse/mbedtls&distro=openSUSE%20Leap%2016.0

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -3.6.6-bp160.1.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    openSUSE-SU-2026:21144-1 | CVE-DB