CVE-2025-52496CWE-733

Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur

High · published July 4, 2025

CVSS v3.1
7.8
EPSS
0%
Percentile
8.6
In the wild
Unconfirmed
What it is

Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may be able to extract an AES key from a multithreaded program, or perform a GCM forgery.

The record
Technical detail
CVSS v3.1
7.8 · HIGH
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00189 · 8.6th percentile
Weakness
CWE-733 · Compiler Optimization Removal or Modification of Security-critical Code
Published
2025-07-04T00:00Z
EPSS history
Timeline
  • 04 JUL 00:00Z
    Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur
    cvelistv5