CVE-2025-52496CWE-733
Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur
High · published July 4, 2025
What it is
Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may be able to extract an AES key from a multithreaded program, or perform a GCM forgery.
The record
Technical detail
- CVSS v3.1
- 7.8 · HIGH
- Vector
- CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00189 · 8.6th percentile
- Weakness
- CWE-733 · Compiler Optimization Removal or Modification of Security-critical Code
- Published
- 2025-07-04T00:00Z
EPSS history
Timeline