CVE Vulnerabilities

CVE-2025-52496

Compiler Optimization Removal or Modification of Security-critical Code

Published: Jul 04, 2025 | Modified: Jul 08, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may be able to extract an AES key from a multithreaded program, or perform a GCM forgery.

Weakness

The developer builds a security-critical protection mechanism into the software, but the compiler optimizes the program such that the mechanism is removed or modified.

Affected Software

Name Vendor Start Version End Version
Mbedtls Ubuntu oracular *

References