This update for mbedtls fixes the following issues:
Changes in mbedtls:
- Update to 3.6.6 (LTS maintenance update from 3.6.1); security fixes
accumulated across the 3.6.2-3.6.6 releases:
* CVE-2024-49195 (boo#1231708): buffer underrun in pkwrite when
writing an opaque key pair
* CVE-2025-27809 (boo#1240051): certificate verification accepted
arbitrary hostnames
* CVE-2025-27810 (boo#1240052): possible authentication bypass on
failed memory allocation / hardware errors
* CVE-2025-47917 (boo#1246783): misleading memory management in
mbedtls_x509_string_to_names()
* CVE-2025-48965 (boo#1246784): NULL pointer dereference after
mbedtls_asn1_store_named_data()
* CVE-2025-49087 (boo#1246973): timing side channel in PKCS#7
padding removal
* CVE-2025-49600 (boo#1245808): unchecked return values in LMS
verification allow signature bypass via fault injection
* CVE-2025-49601 (boo#1245809): out-of-bounds read in
mbedtls_lms_import_public_key()
...
Read the Full Advisory- openSUSE Leap 16.0:
libeverest-3.6.6-bp160.1.1
libeverest-x86-64-v3-3.6.6-bp160.1.1
libmbedcrypto16-3.6.6-bp160.1.1
libmbedcrypto16-x86-64-v3-3.6.6-bp160.1.1
libmbedtls21-3.6.6-bp160.1.1
libmbedtls21-x86-64-v3-3.6.6-bp160.1.1
libmbedx509-7-3.6.6-bp160.1.1
libmbedx509-7-x86-64-v3-3.6.6-bp160.1.1
libp256m-3.6.6-bp160.1.1
libp256m-x86-64-v3-3.6.6-bp160.1.1
mbedtls-devel-3.6.6-bp160.1.1
* bsc#1231708
* bsc#1240051
* bsc#1240052
* bsc#1245808
* bsc#1245809
* bsc#1245810
* bsc#1245811
* bsc#1246783
* bsc#1246784
* bsc#1246973
* bsc#1252341
* bsc#1252454
References:
* https://www.suse.com/security/cve/CVE-2024-49195.html
* https://www.suse.com/security/cve/CVE-2025-27809.html
* https://www.suse.com/security/cve/CVE-2025-27810.html
* https://www.suse.com/security/cve/CVE-2025-47917.html
* https://www.suse.com/security/cve/CVE-2025-48965.html
* https://www.suse.com/security/cve/CVE-2025-49087.html
* https://www.suse.com/security/cve/CVE-2025-49600.html
* https://www.suse.com/security/cve/CVE-2025-49601.html
* https://www.suse.com/security/cve/CVE-2025-52496.html
* https://www.suse.com/security/cve/CVE-2025-52497.html
* https://www.suse.com/security/cve/CVE-2025-54764.html
* https://www.suse.com/security/cve/CVE-2025-59438.html
* https://www.suse.com/security/cve/CVE-2026-25833.html
* https://www.suse.com/security/cve/CVE-2026-25834.html
* https://www.suse.com/security/cve/CVE-2026-25835.html
Get the latest Linux and open source security news straight to your inbox.