Covert Timing Channel in mbed TLS - CVE-2025-59438

 

Covert Timing Channel in mbed TLS - CVE-2025-59438

Published: October 17, 2025


Vulnerability identifier: #VU117336
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-59438
CWE-ID: CWE-385
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to perform padding oracle attack.

The vulnerability exists due to padding oracle through timing of cipher error reporting. An attacker can recover plain texts encrypted with CBC-PKCS7 or other symmetric encryption mode using padding when it is decrypted through the PSA API.


Affected software

mbed TLS
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Fedora
Server Applications Module
SUSE Package Hub 15
mbedtls
qemu-uefi-aarch64
qemu-ovmf-x86_64
qemu-uefi-aarch32
qemu-ovmf-x86_64-debug
ovmf-tools
ovmf

How to mitigate CVE-2025-59438

Install updates from vendor's website.

mbed TLS - update to 3.6.5
mbedtls - addressed in versions 2.28.10-2.fc41, 3.6.4-2.el10_2, 3.6.5-1.el10_0, 3.6.5-1.el10_1, 3.6.5-1.el10_2, 3.6.5-1.fc42, 3.6.5-1.fc43, 3.6.6-1.el10_1, 3.6.6-1.el10_2, 3.6.6-1.el10_3
qemu-uefi-aarch64 - update to 202408-150700.3.15.1
qemu-ovmf-x86_64 - update to 202408-150700.3.15.1
qemu-uefi-aarch32 - update to 202408-150700.3.15.1
qemu-ovmf-x86_64-debug - update to 202408-150700.3.15.1
ovmf-tools - update to 202408-150700.3.15.1
ovmf - update to 202408-150700.3.15.1

External References

Related Security Bulletins