SUSE alert openSUSE-SU-2026:0214-1 (mbedtls)
| From: | maintenance@opensuse.org | |
| To: | security-announce@lists.opensuse.org | |
| Subject: | openSUSE-SU-2026:0214-1: important: Security update for mbedtls | |
| Date: | Thu, 25 Jun 2026 15:05:02 +0200 | |
| Message-ID: | <20260625130502.38681FCE4@maintenance.suse.de> | |
| Archive-link: | Article |
openSUSE Security Update: Security update for mbedtls ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0214-1 Rating: important References: #1245808 #1245809 #1245810 #1245811 #1252454 #1261527 Cross-References: CVE-2025-49600 CVE-2025-49601 CVE-2025-52496 CVE-2025-52497 CVE-2025-59438 CVE-2026-34874 CVSS scores: CVE-2025-59438 (SUSE): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-34874 (SUSE): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes 6 vulnerabilities is now available. Description: This update for mbedtls fixes the following issues: - Update to the 3.6 LTS line (3.6.6) to fix several security issues; this bumps the SONAMEs (libmbedtls20 -> libmbedtls21, libmbedcrypto15 -> libmbedcrypto16, libmbedx509-6 -> libmbedx509-7): * CVE-2025-49600: possible LMS signature forgery due to unchecked return values in mbedtls_lms_verify (boo#1245808) * CVE-2025-49601: out-of-bounds read in mbedtls_lms_import_public_key on truncated input (boo#1245809) * CVE-2025-52496: race condition in AESNI detection allowing AES key extraction or GCM forgery (boo#1245810) * CVE-2025-52497: one-byte heap buffer underflow in PEM parsing (boo#1245811) * CVE-2025-59438: observable timing discrepancy (padding oracle) in CBC-PKCS7 (boo#1252454) * CVE-2026-34874: NULL pointer dereference in X.509 distinguished-name parsing (boo#1261527) - Ship the pkg-config files in the -devel subpackage Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-214=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64): libeverest-3.6.6-bp157.2.3.1 libmbedcrypto16-3.6.6-bp157.2.3.1 libmbedtls21-3.6.6-bp157.2.3.1 libmbedx509-7-3.6.6-bp157.2.3.1 libp256m-3.6.6-bp157.2.3.1 mbedtls-devel-3.6.6-bp157.2.3.1 - openSUSE Backports SLE-15-SP7 (aarch64_ilp32): libeverest-64bit-3.6.6-bp157.2.3.1 libmbedcrypto16-64bit-3.6.6-bp157.2.3.1 libmbedtls21-64bit-3.6.6-bp157.2.3.1 libmbedx509-7-64bit-3.6.6-bp157.2.3.1 libp256m-64bit-3.6.6-bp157.2.3.1 - openSUSE Backports SLE-15-SP7 (x86_64): libeverest-32bit-3.6.6-bp157.2.3.1 libmbedcrypto16-32bit-3.6.6-bp157.2.3.1 libmbedtls21-32bit-3.6.6-bp157.2.3.1 libmbedx509-7-32bit-3.6.6-bp157.2.3.1 libp256m-32bit-3.6.6-bp157.2.3.1 References: https://www.suse.com/security/cve/CVE-2025-49600.html https://www.suse.com/security/cve/CVE-2025-49601.html https://www.suse.com/security/cve/CVE-2025-52496.html https://www.suse.com/security/cve/CVE-2025-52497.html https://www.suse.com/security/cve/CVE-2025-59438.html https://www.suse.com/security/cve/CVE-2026-34874.html https://bugzilla.suse.com/1245808 https://bugzilla.suse.com/1245809 https://bugzilla.suse.com/1245810 https://bugzilla.suse.com/1245811 https://bugzilla.suse.com/1252454 https://bugzilla.suse.com/1261527
