CVE-2025-49087

Name
CVE-2025-49087
Description
In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing discrepancy in block cipher padding removal allows an attacker to recover the plaintext when PKCS#7 padding mode is used.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://github.com/Mbed-TLS/mbedtls-docs/blob/main/security-advisories/mbedtls-security-advisory-2025-06-5.md
cve@mitre.org https://mbed-tls.readthedocs.io/en/latest/tech-updates/security-advisories/

Match rules

CPE URI Source package Min version Max version
mbedtls >= 3.6.1 < 3.6.4
cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:* mbed_tls >= 3.6.1 < 3.6.4

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
mbedtls edge-main 3.6.4-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
mbedtls edge-main 3.6.3.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mbedtls edge-main 3.6.3-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mbedtls edge-main 3.6.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mbedtls edge-main 3.6.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mbedtls 3.22-main 3.6.4-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
mbedtls 3.22-main 3.6.3.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mbedtls 3.22-main 3.6.3-r0 None possibly vulnerable
mbedtls 3.22-main 3.6.2-r0 None possibly vulnerable
mbedtls 3.22-main 3.6.1-r0 None possibly vulnerable
mbedtls 3.21-main 3.6.4-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
mbedtls 3.21-main 3.6.3-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mbedtls 3.21-main 3.6.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mbedtls 3.21-main 3.6.1-r0 None possibly vulnerable
mbedtls 3.20-main 3.6.4-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
mbedtls 3.20-main 3.6.3-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mbedtls 3.20-main 3.6.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
mbedtls 3.20-main 3.6.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable