security advisoryinformation leakdebian
CVE-2025-59438 Observable Timing Discrepancy. The presence of a padding error could leak through timings, enabling the attacker to recover information about the secret. CVE-2026-34871. Debian LTS Advisory DLA-4551-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Andrej Shadura April 27, 2026 https://wiki.debian.org/LTS Package : mbedtls Version : 2.16.9-0.1+deb11u4 CVE ID : CVE-2025-59438 CVE-2026-34871 CVE-2025-59438 Observable Timing Discrepancy. The presence of a padding error could leak through timings, enabling the attacker to recover information about the secret. CVE-2026-34871 On systems where getrandom() was not available, /dev/urandom would be used a fallback instead of /dev/random. For Debian 11 bullseye, these problems have been fixed in version 2.16.9-0.1+deb11u4. We recommend that you upgrade your mbedtls packages. For the detailed security status of mbedtls please refer to its security tracker page at: https://security-tracker.debian.org/tracker/mbedtls Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Explore the Debian LTS security advisory DLA-4551-1 for mbedtls vulnerabilities, including timing discrepancies and update recommendations.. Debian LTS, mbedtls security, timing discrepancy, information leak, security advisories. . Severity: Important. LinuxSecurity.com Team
Apr 27, 2026
•Important
Debian LTS