Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4274-1 | mbedtls security update |
EUVD |
EUVD-2025-20081 | Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may be able to extract an AES key from a multithreaded program, or perform a GCM forgery. |
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 22 Sep 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arm
Arm mbed Tls |
|
| CPEs | cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Arm
Arm mbed Tls |
Tue, 08 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Jul 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may be able to extract an AES key from a multithreaded program, or perform a GCM forgery. | |
| Weaknesses | CWE-733 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-03T20:05:50.713Z
Reserved: 2025-06-17T00:00:00.000Z
Link: CVE-2025-52496
Updated: 2025-11-03T20:05:50.713Z
Status : Modified
Published: 2025-07-04T15:15:22.633
Modified: 2025-11-03T20:19:13.020
Link: CVE-2025-52496
No data.
OpenCVE Enrichment
Updated: 2025-07-13T21:47:58Z
Debian DLA
EUVD