Use of insufficiently random values in mbed TLS - CVE-2026-25835
Published: April 2, 2026
Vulnerability details
The vulnerability allows a local user to obtain predictable random numbers.
The vulnerability exists due to insufficient randomness in the PSA random generator when application state is cloned. A local user can exploit system or application cloning scenarios such as fork(), VM cloning, or hibernation resume to cause multiple instances to generate identical random outputs, enabling prediction of cryptographic keys and nonces.
Applications that use the PSA random generator are affected when the system or application state is cloned without reseeding the generator. This includes scenarios such as fork() on Unix-like systems, virtual machine cloning, and resuming hibernation images multiple times.
Affected software
TF-PSA-Crypto
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Micro
Fedora
Server Applications Module
SUSE Package Hub 15
mbedtls
qemu-uefi-aarch64
qemu-ovmf-x86_64
qemu-uefi-aarch32
qemu-ovmf-x86_64-debug
ovmf
ovmf-tools
How to mitigate CVE-2026-25835
TF-PSA-Crypto - update to 1.1.0
mbedtls - addressed in versions 3.6.6-1.el10_1, 3.6.6-1.el10_2, 3.6.6-1.el10_3, 3.6.6-1.fc42, 3.6.6-1.fc43, 3.6.6-1.fc44
qemu-uefi-aarch64 - addressed in versions 202408-150700.3.18.1, 202502-160000.5.1
qemu-ovmf-x86_64 - addressed in versions 202408-150700.3.18.1, 202502-160000.5.1
qemu-uefi-aarch32 - update to 202408-150700.3.18.1
qemu-ovmf-x86_64-debug - update to 202408-150700.3.18.1
ovmf - update to 202408-150700.3.18.1
ovmf-tools - update to 202408-150700.3.18.1
External References
Related Security Bulletins
- Multiple vulnerabilities in ARM mbed TLS
- Multiple vulnerabilities in ARM TF-PSA-Crypto
- Fedora 42 update for mbedtls
- Fedora 43 update for mbedtls
- Fedora 44 update for mbedtls
- Fedora EPEL 10.1 update for mbedtls
- Fedora EPEL 10.2 update for mbedtls
- Fedora EPEL 10.3 update for mbedtls
- SUSE update for ovmf
- SUSE update for ovmf