Alerts This Week
Warning Icon 1 1,365
Alerts This Week
Warning Icon 1 1,365

openSUSE Leap 16.0 mbedtls Critical Buffer Overflow Vuln 2026-21144-1

opensuse
Calendar Grey June 30, 2026
Dist Opensuse Esm H88
openSUSE updates mbedtls addressing 15 vulnerabilities including critical threats requiring immediate attention.
An update that solves 15 vulnerabilities and has 12 bug fixes can now be installed.

Description

This update for mbedtls fixes the following issues:

Changes in mbedtls:

- Update to 3.6.6 (LTS maintenance update from 3.6.1); security fixes

accumulated across the 3.6.2-3.6.6 releases:

* CVE-2024-49195 (boo#1231708): buffer underrun in pkwrite when

writing an opaque key pair

* CVE-2025-27809 (boo#1240051): certificate verification accepted

arbitrary hostnames

* CVE-2025-27810 (boo#1240052): possible authentication bypass on

failed memory allocation / hardware errors

* CVE-2025-47917 (boo#1246783): misleading memory management in

mbedtls_x509_string_to_names()

* CVE-2025-48965 (boo#1246784): NULL pointer dereference after

mbedtls_asn1_store_named_data()

* CVE-2025-49087 (boo#1246973): timing side channel in PKCS#7

padding removal

* CVE-2025-49600 (boo#1245808): unchecked return values in LMS

verification allow signature bypass via fault injection

* CVE-2025-49601 (boo#1245809): out-of-bounds read in

mbedtls_lms_import_public_key()

...

Read the Full Advisory

Patch

Package List

- openSUSE Leap 16.0:

libeverest-3.6.6-bp160.1.1

libeverest-x86-64-v3-3.6.6-bp160.1.1

libmbedcrypto16-3.6.6-bp160.1.1

libmbedcrypto16-x86-64-v3-3.6.6-bp160.1.1

libmbedtls21-3.6.6-bp160.1.1

libmbedtls21-x86-64-v3-3.6.6-bp160.1.1

libmbedx509-7-3.6.6-bp160.1.1

libmbedx509-7-x86-64-v3-3.6.6-bp160.1.1

libp256m-3.6.6-bp160.1.1

libp256m-x86-64-v3-3.6.6-bp160.1.1

mbedtls-devel-3.6.6-bp160.1.1

References

* bsc#1231708

* bsc#1240051

* bsc#1240052

* bsc#1245808

* bsc#1245809

* bsc#1245810

* bsc#1245811

* bsc#1246783

* bsc#1246784

* bsc#1246973

* bsc#1252341

* bsc#1252454

References:

* https://www.suse.com/security/cve/CVE-2024-49195.html

* https://www.suse.com/security/cve/CVE-2025-27809.html

* https://www.suse.com/security/cve/CVE-2025-27810.html

* https://www.suse.com/security/cve/CVE-2025-47917.html

* https://www.suse.com/security/cve/CVE-2025-48965.html

* https://www.suse.com/security/cve/CVE-2025-49087.html

* https://www.suse.com/security/cve/CVE-2025-49600.html

* https://www.suse.com/security/cve/CVE-2025-49601.html

* https://www.suse.com/security/cve/CVE-2025-52496.html

* https://www.suse.com/security/cve/CVE-2025-52497.html

* https://www.suse.com/security/cve/CVE-2025-54764.html

* https://www.suse.com/security/cve/CVE-2025-59438.html

* https://www.suse.com/security/cve/CVE-2026-25833.html

* https://www.suse.com/security/cve/CVE-2026-25834.html

* https://www.suse.com/security/cve/CVE-2026-25835.html

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:21144-1
Rating: critical
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here