High severity7.8NVD Advisory· Published Jul 4, 2025· Updated Jun 17, 2026
CVE-2025-52496
CVE-2025-52496
Description
Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may be able to extract an AES key from a multithreaded program, or perform a GCM forgery.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- osv-coords3 versionspkg:rpm/opensuse/mbedtls&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/mbedtls-2&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/mbedtls-2&distro=openSUSE%20Leap%2016.0
< 3.6.6-bp160.1.1+ 2 more
- (no CPE)range: < 3.6.6-bp160.1.1
- (no CPE)range: < 2.28.10-5.1
- (no CPE)range: < 2.28.10-bp160.2.1
- Range: <3.6.4
- Mbed/mbedtlsv5Range: 0
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.