CVE Vulnerabilities

CVE-2025-27810

Use of Uninitialized Resource

Published: Mar 25, 2025 | Modified: Oct 30, 2025
CVSS 3.x
4.8
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.

Weakness

The product uses or accesses a resource that has not been initialized.

Affected Software

NameVendorStart VersionEnd Version
Mbed_tlsArm*2.28.10 (excluding)
Mbed_tlsArm3.0.0 (including)3.6.3 (excluding)
MbedtlsUbuntudevel*
MbedtlsUbuntuesm-apps/bionic*
MbedtlsUbuntuesm-apps/focal*
MbedtlsUbuntuesm-apps/jammy*
MbedtlsUbuntuesm-apps/noble*
MbedtlsUbuntuesm-apps/xenial*
MbedtlsUbuntufocal*
MbedtlsUbuntujammy*
MbedtlsUbuntunoble*
MbedtlsUbuntuoracular*
MbedtlsUbuntuplucky*
MbedtlsUbuntuquesting*
MbedtlsUbuntuupstream*

Potential Mitigations

References