CVE-2026-25832

low
Assigned by CNA: mitre
Published 2026-09-14 · Modified 2026-09-14
CVSS v3
3.7
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS v4 NEW
not yet in upstream
VIR risk
3.7

Description

In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.

Predictions

Exploit likelihood
47%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2026-25832 NameCVE-2026-25832 SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) Vulnerable and fixed packages The table below lists information on source packages. Source PackageReleaseVersionStatus mbedtls (PTS)bullseye2.16.9-0.1vulnerable bullseye…

CVE-2026-25832

NameCVE-2026-25832
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mbedtls (PTS)bullseye2.16.9-0.1vulnerable
bullseye (security)2.16.9-0.1+deb11u4vulnerable
bookworm2.28.3-1vulnerable
trixie3.6.5-0.1~deb13u1vulnerable
forky, sid3.6.7-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mbedtlssourcebookworm(unfixed)end-of-life
mbedtlssource(unstable)3.6.7-2

Notes

[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
[bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)[bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)

OS impact

debian Debian Mixed 5 releases
VersionStatusFixed in
trixie Affected
sid Fixed 3.6.7-2
forky Fixed 3.6.7-2
bullseye Affected
bookworm Affected
alpine Alpine Fixed 4 releases
VersionStatusFixed in
v3.24 Fixed 4.1.1-r0
v3.23 Fixed 3.6.7-r0
v3.22 Fixed 3.6.7-r0
v3.21 Fixed 3.6.7-r0

References

CWEs

CWE-669

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.