← Back

CVE-2025-52496

nvd nist
Published: Jul 4, 2025Modified: Nov 3, 2025

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Exploitability: 1.4 / Impact: 5.8
Source: NVD

Description

Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may be able to extract an AES key from a multithreaded program, or perform a GCM forgery.

Affected (1)

Products: Arm: Mbed Tls
1 product
Mbed Tls
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.6.4

Timeline

No history available yet.