Alerts This Week
Warning Icon 1 640
Alerts This Week
Warning Icon 1 640

Fedora 42 mbedtls Critical Update Fixes Buffer Underflow in Resumption

fedora
Calendar Grey April 18, 2026
Dist Fedora Esm H88
Critical Fedora 42 mbedtls update addresses serious security issues such as buffer underflow and session resumption.
Update to 3.6.6

Summary

Mbed TLS is a light-weight open source cryptographic and SSL/TLS

library written in C. Mbed TLS makes it easy for developers to include

cryptographic and SSL/TLS capabilities in their (embedded)

applications with as little hassle as possible.

Update Information:

Update to 3.6.6

Change Log

* Thu Apr 2 2026 Peter Robinson - 3.6.6-1 - Update to 3.6.6 * Fri Jan 16 2026 Fedora Release Engineering - 3.6.5-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild

References


[ 1 ] Bug #2340826 - mbedtls: FTBFS in Fedora rawhide/f42 https://bugzilla.redhat.com/show_bug.cgi?id=2340826 [ 2 ] Bug #2454030 - CVE-2026-25833 mbedtls: buffer underflow in x509_inet_pton_ipv6() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454030 [ 3 ] Bug #2454045 - CVE-2026-34874 mbedtls: NULL pointer dereference when setting a distinguished name [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454045 [ 4 ] Bug #2454085 - CVE-2026-34871 mbedtls: entropy on Linux can fall back to /dev/urandom [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454085 [ 5 ] Bug #2454116 - CVE-2026-25835 mbedtls: PSA random generator cloning [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454116 [ 6 ] Bug #2454193 - CVE-2026-34873 mbedtls: Mbed TLS: Client impersonation during TLS 1.3 session resumption [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454193

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-10443c65e3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: mbedtls
Product: Fedora 42
Version: 3.6.6
Release: 1.fc42
Summary: Light-weight cryptographic and SSL/TLS library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here