Name | CVE-2025-59438 |
Description | Mbed TLS through 3.6.4 has an Observable Timing Discrepancy. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Vulnerable and fixed packages
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|
mbedtls (PTS) | bullseye | 2.16.9-0.1 | vulnerable |
| bullseye (security) | 2.16.9-0.1+deb11u3 | vulnerable |
| bookworm | 2.28.3-1 | vulnerable |
| forky, sid, trixie | 3.6.4-2 | vulnerable |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|
mbedtls | source | (unstable) | (unfixed) | | | |
Notes
https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2025-10-invalid-padding-error/
https://github.com/Mbed-TLS/mbedtls/commit/155de2ab775e77ab6fa81bf2b1e6e63768123bc1 (mbedtls-3.6.5)
https://github.com/Mbed-TLS/mbedtls/commit/d179dc80a5b13189c79fe4531eacb28698a7a0e9 (mbedtls-3.6.5)
https://github.com/Mbed-TLS/mbedtls/commit/e74b42832e4af11606ef8aae2c9404b4acaa2c6d (mbedtls-3.6.5)
https://github.com/Mbed-TLS/mbedtls/commit/3b380daedbce9fae3e7ed7e84f18e97876e7e6f3 (mbedtls-3.6.5)
https://github.com/Mbed-TLS/mbedtls/commit/04dfd704325a6dbc2a13eb7f418eaca9ae9ca549 (mbedtls-3.6.5)