CVE-2025-52497Off-by-one Error in Mbedtls

CWE-193Off-by-one Error8 documents7 sources
Severity
4.8MEDIUMNVD
OSV9.8
EPSS
0.1%
top 74.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 4
Latest updateMar 25

Description

Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer underflow, in mbedtls_pem_read_buffer and two mbedtls_pk_parse functions, via untrusted PEM input.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:LExploitability: 2.2 | Impact: 2.5

Affected Packages4 packages

CVEListV5mbed/mbedtls< 3.6.4
NVDarm/mbed_tls< 3.6.4
Debianmbed/mbedtls< 2.16.9-0.1+deb11u2+2
Ubuntumbed/mbedtls< 2.8.0-1ubuntu0.1~esm1+3

🔴Vulnerability Details

4
OSV
mbedtls vulnerabilities2026-03-25
GHSA
GHSA-3p24-8mw5-x2hx: Mbed TLS before 32025-07-04
CVEList
CVE-2025-52497: Mbed TLS before 32025-07-04
OSV
CVE-2025-52497: Mbed TLS before 32025-07-04

📋Vendor Advisories

2
Ubuntu
Mbed TLS vulnerabilities2026-03-25
Debian
CVE-2025-52497: mbedtls - Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer underflow, in...2025

💬Community

1
Bugzilla
CVE-2025-52497 micropython: Mbed TLS PEM Parsing Buffer Underflow [fedora-all]2025-07-07
CVE-2025-52497 — Off-by-one Error in Mbed Mbedtls | cvebase