Improper access control in mbed TLS - CVE-2026-25834
Published: April 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass security policies.
The vulnerability exists due to improper access control in the TLS 1.2 signature algorithm negotiation component when processing server responses during handshake. A remote attacker can send a specially crafted server response to cause the client to accept a signature algorithm not previously advertised in the client hello, leading to a security policy bypass.
The issue affects only TLS 1.2 connections and occurs when the server ignores the signature algorithms extension sent by the client. The client fails to enforce the configured policy via mbedtls_ssl_conf_sig_algs().
Affected software
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Micro
Fedora
Server Applications Module
SUSE Package Hub 15
mbedtls
qemu-uefi-aarch64
qemu-ovmf-x86_64
qemu-uefi-aarch32
qemu-ovmf-x86_64-debug
ovmf
ovmf-tools
How to mitigate CVE-2026-25834
mbedtls - addressed in versions 3.6.6-1.el10_1, 3.6.6-1.el10_2, 3.6.6-1.el10_3
qemu-uefi-aarch64 - addressed in versions 202408-150700.3.18.1, 202502-160000.5.1
qemu-ovmf-x86_64 - addressed in versions 202408-150700.3.18.1, 202502-160000.5.1
qemu-uefi-aarch32 - update to 202408-150700.3.18.1
qemu-ovmf-x86_64-debug - update to 202408-150700.3.18.1
ovmf - update to 202408-150700.3.18.1
ovmf-tools - update to 202408-150700.3.18.1