Medium severity6.2NVD Advisory· Published Oct 20, 2025· Updated Jun 17, 2026
CVE-2025-54764
CVE-2025-54764
Description
Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_inv or mbedtls_mpi_gcd.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- osv-coords2 versionspkg:rpm/opensuse/mbedtls&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/mbedtls&distro=openSUSE%20Leap%2016.0
< 3.6.5-1.1+ 1 more
- (no CPE)range: < 3.6.5-1.1
- (no CPE)range: < 3.6.6-bp160.1.1
Patches
Vulnerability mechanics
References
2- mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2025-10-ssbleed-mstep/nvdExploitVendor Advisory
- mbed-tls.readthedocs.io/en/latest/tech-updates/security-advisories/nvdVendor Advisory
News mentions
0No linked articles in our index yet.