Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Fedora 43 mbedtls Critical Buffer Underflow NULL Pointer 2026-8c332fbf00

fedora
Calendar Grey April 10, 2026
Dist Fedora Esm H88
The mbedtls update addresses critical issues in Fedora 43 with comprehensive fixes for buffer underflows and NULL pointer dereferences.
Update to 3.6.6

Summary

Mbed TLS is a light-weight open source cryptographic and SSL/TLS

library written in C. Mbed TLS makes it easy for developers to include

cryptographic and SSL/TLS capabilities in their (embedded)

applications with as little hassle as possible.

Update Information:

Update to 3.6.6

Change Log

* Thu Apr 2 2026 Peter Robinson - 3.6.6-1 - Update to 3.6.6 * Fri Jan 16 2026 Fedora Release Engineering - 3.6.5-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild

References


[ 1 ] Bug #2454030 - CVE-2026-25833 mbedtls: buffer underflow in x509_inet_pton_ipv6() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454030 [ 2 ] Bug #2454045 - CVE-2026-34874 mbedtls: NULL pointer dereference when setting a distinguished name [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454045 [ 3 ] Bug #2454085 - CVE-2026-34871 mbedtls: entropy on Linux can fall back to /dev/urandom [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454085 [ 4 ] Bug #2454116 - CVE-2026-25835 mbedtls: PSA random generator cloning [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454116 [ 5 ] Bug #2454193 - CVE-2026-34873 mbedtls: Mbed TLS: Client impersonation during TLS 1.3 session resumption [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454193

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-8c332fbf00' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: mbedtls
Product: Fedora 43
Version: 3.6.6
Release: 1.fc43
Summary: Light-weight cryptographic and SSL/TLS library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here