Bug#1108785: mbedtls: CVE-2025-52496: Race condition in AESNI support d
From Salvatore Bonaccorso@21:1/5 to All on Sat Jul 5 09:40:01 2025
Source: mbedtls
Version: 3.6.3-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for mbedtls.
CVE-2025-52496[0]:
| Mbed TLS before 3.6.4 has a race condition in AESNI detection if
| certain compiler optimizations occur. An attacker may be able to
| extract an AES key from a multithreaded program, or perform a GCM
| forgery.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.