CVE-2025-52496: Race Condition
Published Jul 4, 2025
·Updated
Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may be able to extract an AES key from a multithreaded program, or perform a GCM forgery.
Affected Software
2 affected components
Arm mbed TLS<3.6.4
Arm mbed TLS<3.6.4
Event History
Jul 4, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-52496?
CVE-2025-52496 has a severity rating that reflects a significant risk due to the potential for AES key extraction in multithreaded applications.
2
How do I fix CVE-2025-52496?
To fix CVE-2025-52496, upgrade to Mbed TLS version 3.6.4 or later.
3
What type of applications are affected by CVE-2025-52496?
CVE-2025-52496 affects multithreaded applications that utilize Mbed TLS versions prior to 3.6.4.
4
What issues does CVE-2025-52496 cause?
CVE-2025-52496 can lead to the extraction of AES keys and enable GCM forgery attacks.
5
Who is the vendor of the affected software for CVE-2025-52496?
The affected software, Mbed TLS, is provided by ARM.