{"id":"openSUSE-SU-2026:21145-1","summary":"Security update for mbedtls-2","details":"This update for mbedtls-2 fixes the following issues:\n\nChanges in mbedtls-2:\n\n- Enable SRTP and DTLS protocols needed by some software.\n\n- Update to version 2.28.10:\n  Default behavior changes\n  * In TLS clients, if mbedtls_ssl_set_hostname() has not been called,\n    mbedtls_ssl_handshake() now fails with\n    MBEDTLS_ERR_SSL_CERTIFICATE_VERIFICATION_WITHOUT_HOSTNAME\n    if certificate-based authentication of the server is attempted.\n    This is because authenticating a server without knowing what name\n    to expect is usually insecure. To restore the old behavior, either\n    call mbedtls_ssl_set_hostname() with NULL as the hostname, or\n    enable the new compile-time option\n    MBEDTLS_SSL_CLI_ALLOW_WEAK_CERTIFICATE_VERIFICATION_WITHOUT_HOSTNAME.\n    The content of ssl-\u003ehostname after mbedtls_ssl_set_hostname(ssl, NULL)\n    has changed, see the documentation of the hostname field in the\n    mbedtls_ssl_context struct type for details.\n  Security\n  * Note that TLS clients should generally call mbedtls_ssl_set_hostname()\n    if they use certificate authentication (i.e. not pre-shared keys).\n    Otherwise, in many scenarios, the server could be impersonated.\n    The library will now prevent the handshake and return\n    MBEDTLS_ERR_SSL_CERTIFICATE_VERIFICATION_WITHOUT_HOSTNAME\n    if mbedtls_ssl_set_hostname() has not been called.\n    CVE-2025-27809 (boo#1240051)\n  * Zeroize temporary heap buffers used in PSA operations.\n  * Fix a vulnerability in the TLS 1.2 handshake. If memory allocation failed\n    or there was a cryptographic hardware failure when calculating the\n    Finished message, it could be calculated incorrectly. This would break\n    the security guarantees of the TLS handshake.\n    CVE-2025-27810 (boo#1240052)\n  Bugfix\n  * Use 'mbedtls_net_close' instead of 'close' in 'mbedtls_net_bind'\n    and 'mbedtls_net_connect' to prevent possible double close fd\n    problems. Fixes gh#Mbed-TLS/mbedtls#9711.\n  * Fix compilation on MS-DOS DJGPP. Fixes gh#Mbed-TLS/mbedtls#9813.\n  * Fix missing constraints on the AES-NI inline assembly which is used on\n    GCC-like compilers when building AES for generic x86_64 targets. This\n    may have resulted in incorrect code with some compilers, depending on\n    optimizations. Fixes gh#Mbed-TLS/mbedtls#9819.\n  * Fix issue where psa_key_derivation_input_integer() is not detecting\n    bad state after an operation has been aborted.\n  * Fix definition of MBEDTLS_PRINTF_SIZET to prevent runtime crashes that\n    occurred whenever SSL debugging was enabled on a copy of Mbed TLS built\n    with Visual Studio 2013 or MinGW.\n    Fixes gh#Mbed-TLS/mbedtls#10017.\n  * Remove Everest Visual Studio 2010 compatibility headers, which could\n    shadow standard CRT headers inttypes.h and stdbool.h with incomplete\n    implementatios if placed on the include path, eg. when building Mbed TLS\n    with the .sln file shipped with the project.\n","modified":"2026-06-30T18:24:53.476090522Z","published":"2026-06-22T13:08:31Z","related":["CVE-2024-45157","CVE-2025-27809","CVE-2025-27810"],"upstream":["CVE-2024-45157","CVE-2025-27809","CVE-2025-27810"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1230310"},{"type":"REPORT","url":"https://bugzilla.suse.com/1240051"},{"type":"REPORT","url":"https://bugzilla.suse.com/1240052"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-45157"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-27809"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-27810"}],"affected":[{"package":{"name":"mbedtls-2","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/mbedtls-2&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.28.10-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"libmbedx509-1-x86-64-v3":"2.28.10-bp160.1.1","mbedtls-2-devel":"2.28.10-bp160.1.1","libmbedcrypto7":"2.28.10-bp160.1.1","libmbedcrypto7-x86-64-v3":"2.28.10-bp160.1.1","libmbedtls14":"2.28.10-bp160.1.1","libmbedtls14-x86-64-v3":"2.28.10-bp160.1.1","libmbedx509-1":"2.28.10-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21145-1.json"}}],"schema_version":"1.7.5"}