Medium severity5.4NVD Advisory· Published Mar 25, 2025· Updated Jun 17, 2026
CVE-2025-27810
CVE-2025-27810
Description
Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- osv-coords2 versionspkg:julia/MbedTLS_jll?uuid=c8ffd9c3-330d-5841-b78e-0817d7145fa1pkg:rpm/opensuse/mbedtls-2&distro=openSUSE%20Tumbleweed
< 2.28.10+0+ 1 more
- (no CPE)range: < 2.28.10+0
- (no CPE)range: < 2.28.10-1.1
- Mbed/mbedtlsv5Range: 0
Patches
Vulnerability mechanics
References
2- mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2025-03-2/nvdVendor Advisory
- github.com/Mbed-TLS/mbedtls/releasesnvdRelease Notes
News mentions
0No linked articles in our index yet.