CVE-2025-52496 Information

Description

Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may be able to extract an AES key from a multithreaded program or perform a GCM forgery.

Reference

https://github.com/Mbed-TLS/mbedtls-docs/blob/main/security-advisories/mbedtls-security-advisory-2025-06-1.md

CNNVD-202507-498 (Published: 2025-07-04)

Share on: