{"id":"openSUSE-SU-2026:21864-1","summary":"Security update for mbedtls-2","details":"This update for mbedtls-2 fixes the following issues:\n\nChanges in mbedtls-2:\n\n- CVE-2025-52496: race condition in AESNI support detection, AES key\n  disclosure / GCM forgery in multithreaded programs (boo#1245810)\n- CVE-2025-59438: padding oracle through timing of cipher error\n  reporting (boo#1252454)\n","modified":"2026-09-17T18:23:34.200833992Z","published":"2026-09-16T15:11:09Z","related":["CVE-2025-52496","CVE-2025-59438"],"upstream":["CVE-2025-52496","CVE-2025-59438"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1245810"},{"type":"REPORT","url":"https://bugzilla.suse.com/1252454"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-52496"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-59438"}],"affected":[{"package":{"name":"mbedtls-2","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/mbedtls-2&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.28.10-bp160.2.1"}]}],"ecosystem_specific":{"binaries":[{"libmbedcrypto7-x86-64-v3":"2.28.10-bp160.2.1","libmbedtls14":"2.28.10-bp160.2.1","libmbedtls14-x86-64-v3":"2.28.10-bp160.2.1","libmbedx509-1":"2.28.10-bp160.2.1","libmbedx509-1-x86-64-v3":"2.28.10-bp160.2.1","mbedtls-2-devel":"2.28.10-bp160.2.1","libmbedcrypto7":"2.28.10-bp160.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21864-1.json"}}],"schema_version":"1.9.0"}