CVE-2026-25832
Description
In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Mitigation details
CVE-2026-25832 NameCVE-2026-25832 SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) Vulnerable and fixed packages The table below lists information on source packages. Source PackageReleaseVersionStatus mbedtls (PTS)bullseye2.16.9-0.1vulnerable bullseye…
CVE-2026-25832
| Name | CVE-2026-25832 |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| mbedtls (PTS) | bullseye | 2.16.9-0.1 | vulnerable |
| bullseye (security) | 2.16.9-0.1+deb11u4 | vulnerable | |
| bookworm | 2.28.3-1 | vulnerable | |
| trixie | 3.6.5-0.1~deb13u1 | vulnerable | |
| forky, sid | 3.6.7-3 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| mbedtls | source | bookworm | (unfixed) | end-of-life | ||
| mbedtls | source | (unstable) | 3.6.7-2 |
Notes
[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
[bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
Apply commands
[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)[bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
OS impact
Debian Mixed 5 releases
| Version | Status | Fixed in |
|---|---|---|
| trixie | Affected | — |
| sid | Fixed | 3.6.7-2 |
| forky | Fixed | 3.6.7-2 |
| bullseye | Affected | — |
| bookworm | Affected | — |
Alpine Fixed 4 releases
| Version | Status | Fixed in |
|---|---|---|
| v3.24 | Fixed | 4.1.1-r0 |
| v3.23 | Fixed | 3.6.7-r0 |
| v3.22 | Fixed | 3.6.7-r0 |
| v3.21 | Fixed | 3.6.7-r0 |
References
- https://security-tracker.debian.org/tracker/CVE-2026-25832
- https://security.alpinelinux.org/vuln/CVE-2026-25832
- https://pkgs.alpinelinux.org/packages?name=mbedtls
- https://pkgs.alpinelinux.org/packages?name=mbedtls3
- https://mbed-tls.readthedocs.io/en/latest/security-advisories/
- https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-tls13-hrr-unadvertised-group/
CWEs
CWE-669
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.