Bug#1108786: mbedtls: CVE-2025-52497: Heap buffer under-read when parsi
From Salvatore Bonaccorso@21:1/5 to All on Sat Jul 5 09:40:01 2025
Source: mbedtls
Version: 3.6.3-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for mbedtls.
CVE-2025-52497[0]:
| Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer
| underflow, in mbedtls_pem_read_buffer and two mbedtls_pk_parse
| functions, via untrusted PEM input.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.