Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer underflow, in mbedtls_pem_read_buffer and two mbedtls_pk_parse functions, via untrusted PEM input.
Metrics
Affected Vendors & Products
References
History
Tue, 08 Jul 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 04 Jul 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer underflow, in mbedtls_pem_read_buffer and two mbedtls_pk_parse functions, via untrusted PEM input. | |
Weaknesses | CWE-193 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-07-04T00:00:00.000Z
Updated: 2025-07-08T14:36:28.722Z
Reserved: 2025-06-17T00:00:00.000Z
Link: CVE-2025-52497

Updated: 2025-07-08T14:35:10.289Z

Status : Awaiting Analysis
Published: 2025-07-04T15:15:22.787
Modified: 2025-07-08T16:18:53.607
Link: CVE-2025-52497

No data.