CVE-2025-54764

Name
CVE-2025-54764
Description
Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_inv or mbedtls_mpi_gcd.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2025-10-ssbleed-mstep/
cve@mitre.org https://mbed-tls.readthedocs.io/en/latest/tech-updates/security-advisories/

Match rules

CPE URI Source package Min version Max version
n/a == n/a == n/a
cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:* mbed_tls >= None < 3.6.5

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
mbedtls edge-main 3.6.5-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
mbedtls 3.22-main 3.6.5-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
mbedtls 3.21-main 3.6.5-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
mbedtls 3.20-main 3.6.5-r0 Natanael Copa <ncopa@alpinelinux.org> fixed