Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer underflow, in mbedtls_pem_read_buffer and two mbedtls_pk_parse functions, via untrusted PEM input.
Metrics
Affected Vendors & Products
References
History
Thu, 17 Jul 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Arm
Arm mbed Tls |
|
CPEs | cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:* | |
Vendors & Products |
Arm
Arm mbed Tls |
Tue, 08 Jul 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 04 Jul 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer underflow, in mbedtls_pem_read_buffer and two mbedtls_pk_parse functions, via untrusted PEM input. | |
Weaknesses | CWE-193 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-07-04T00:00:00.000Z
Updated: 2025-07-08T14:36:28.722Z
Reserved: 2025-06-17T00:00:00.000Z
Link: CVE-2025-52497

Updated: 2025-07-08T14:35:10.289Z

Status : Analyzed
Published: 2025-07-04T15:15:22.787
Modified: 2025-07-17T16:00:42.443
Link: CVE-2025-52497

No data.