openSUSE-SU-2026:21144-1
Dashboard / Vulnerabilities / openSUSE-SU-2026:21144-1
openSUSE-SU-2026:21144-1
Summary: Security update for mbedtls
Details: This update for mbedtls fixes the following issues: Changes in mbedtls: - Update to 3.6.6 (LTS maintenance update from 3.6.1); security fixes accumulated across the 3.6.2-3.6.6 releases: * CVE-2024-49195 (boo#1231708): buffer underrun in pkwrite when writing an opaque key pair * CVE-2025-27809 (boo#1240051): certificate verification accepted arbitrary hostnames * CVE-2025-27810 (boo#1240052): possible authentication bypass on failed memory allocation / hardware errors * CVE-2025-47917 (boo#1246783): misleading memory management in mbedtls_x509_string_to_names() * CVE-2025-48965 (boo#1246784): NULL pointer dereference after mbedtls_asn1_store_named_data() * CVE-2025-49087 (boo#1246973): timing side channel in PKCS#7 padding removal * CVE-2025-49600 (boo#1245808): unchecked return values in LMS verification allow signature bypass via fault injection * CVE-2025-49601 (boo#1245809): out-of-bounds read in mbedtls_lms_import_public_key() * CVE-2025-52496 (boo#1245810): race in AES-NI support detection can lead to AES key extraction or GCM forgery * CVE-2025-52497 (boo#1245811): one-byte heap underflow when parsing PEM-encrypted material * CVE-2025-54764 (boo#1252341): timing attacks in RSA operations * CVE-2025-59438 (boo#1252454): padding-oracle attack via timing of cipher error reporting * CVE-2026-25833: PSA RNG state duplicated across fork() * CVE-2026-25834: TLS 1.3 HelloRetryRequest man-in-the-middle session-resumption downgrade * CVE-2026-25835: RNG state duplicated when application/VM state is cloned
References: , https://bugzilla.suse.com/1231708, https://bugzilla.suse.com/1240051, https://bugzilla.suse.com/1240052, https://bugzilla.suse.com/1245808, https://bugzilla.suse.com/1245809, https://bugzilla.suse.com/1245810, https://bugzilla.suse.com/1245811, https://bugzilla.suse.com/1246783, https://bugzilla.suse.com/1246784, https://bugzilla.suse.com/1246973, https://bugzilla.suse.com/1252341, https://bugzilla.suse.com/1252454, https://www.suse.com/security/cve/CVE-2024-49195, https://www.suse.com/security/cve/CVE-2025-27809, https://www.suse.com/security/cve/CVE-2025-27810, https://www.suse.com/security/cve/CVE-2025-47917, https://www.suse.com/security/cve/CVE-2025-48965, https://www.suse.com/security/cve/CVE-2025-49087, https://www.suse.com/security/cve/CVE-2025-49600, https://www.suse.com/security/cve/CVE-2025-49601, https://www.suse.com/security/cve/CVE-2025-52496, https://www.suse.com/security/cve/CVE-2025-52497, https://www.suse.com/security/cve/CVE-2025-54764, https://www.suse.com/security/cve/CVE-2025-59438, https://www.suse.com/security/cve/CVE-2026-25833, https://www.suse.com/security/cve/CVE-2026-25834, https://www.suse.com/security/cve/CVE-2026-25835
Affected packages
Package
Name: mbedtls
Purl: pkg:rpm/opensuse/mbedtls&distro=openSUSE%20Leap%2016.0
Affected ranges
Type: ECOSYSTEM
Events:
