CVE-2025-52497

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-52497
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-52497.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-52497
Downstream
Published
2025-07-04T15:15:22Z
Modified
2025-07-08T16:51:02.869874Z
Summary
[none]
Details

Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer underflow, in mbedtlspemreadbuffer and two mbedtlspk_parse functions, via untrusted PEM input.

References

Affected packages

Debian:11 / mbedtls

Package

Name
mbedtls
Purl
pkg:deb/debian/mbedtls?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.16.9-0.1
2.16.9-0.1+deb11u1
2.16.11-0.1
2.16.11-0.2
2.16.11-0.3
2.28.0-0.1
2.28.0-0.2
2.28.0-0.3
2.28.0-1
2.28.0-2
2.28.1-1
2.28.2-1
2.28.3-1
2.28.4-1
2.28.5-1
2.28.6-1
2.28.7-1
2.28.7-1.1~exp1
2.28.7-1.1
2.28.8-1

3.*

3.6.0-1
3.6.0-2
3.6.0-3
3.6.2-1
3.6.2-2
3.6.2-3
3.6.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / mbedtls

Package

Name
mbedtls
Purl
pkg:deb/debian/mbedtls?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.28.3-1
2.28.4-1
2.28.5-1
2.28.6-1
2.28.7-1
2.28.7-1.1~exp1
2.28.7-1.1
2.28.8-1

3.*

3.6.0-1
3.6.0-2
3.6.0-3
3.6.2-1
3.6.2-2
3.6.2-3
3.6.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / mbedtls

Package

Name
mbedtls
Purl
pkg:deb/debian/mbedtls?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.28.3-1
2.28.4-1
2.28.5-1
2.28.6-1
2.28.7-1
2.28.7-1.1~exp1
2.28.7-1.1
2.28.8-1

3.*

3.6.0-1
3.6.0-2
3.6.0-3
3.6.2-1
3.6.2-2
3.6.2-3
3.6.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}