Buffer underflow in mbed TLS - CVE-2026-25833

 

Buffer underflow in mbed TLS - CVE-2026-25833

Published: April 2, 2026


Vulnerability identifier: #VU124806
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-25833
CWE-ID: CWE-124
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in x509_inet_pton_ipv6() when parsing IPv6 address input. A remote attacker can send a specially crafted IPv6 address string to cause a buffer underread of up to 4 bytes, potentially leading to a denial of service.

In rare cases, the buffer underread may cross a page boundary and trigger a memory access violation, resulting in a crash.


Affected software

mbed TLS
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Micro
Server Applications Module
SUSE Package Hub 15
Fedora
mbedtls
qemu-uefi-aarch64
qemu-ovmf-x86_64
qemu-uefi-aarch32
qemu-ovmf-x86_64-debug
ovmf
ovmf-tools

How to mitigate CVE-2026-25833

Install security update from vendor's website.

mbed TLS - addressed in versions 3.6.6, 4.1.0
mbedtls - addressed in versions 3.6.6-1.fc42, 3.6.6-1.fc43, 3.6.6-1.fc44
qemu-uefi-aarch64 - addressed in versions 202408-150700.3.18.1, 202502-160000.5.1
qemu-ovmf-x86_64 - addressed in versions 202408-150700.3.18.1, 202502-160000.5.1
qemu-uefi-aarch32 - update to 202408-150700.3.18.1
qemu-ovmf-x86_64-debug - update to 202408-150700.3.18.1
ovmf - update to 202408-150700.3.18.1
ovmf-tools - update to 202408-150700.3.18.1

External References

Related Security Bulletins