Junglewise Threat Intelligence

CVE-2025-49087: Mbed TLS timing side-channel in block cipher decryption with PKCS#7 padding

CVE-2025-49087 · Severity: medium · CVSS 4 · Published 2025-07-20

Vendors: TrustedFirmware.

Executive brief

Mbed TLS is a widely used open-source cryptographic library that helps devices communicate securely. A flaw in how the library handles encrypted data blocks could allow an attacker to gradually reveal the original, unencrypted information by measuring tiny differences in how long the system takes to process certain requests. This could lead to the exposure of sensitive data like passwords or private messages if the attacker can observe the system's response times.

Technical details

A timing side-channel vulnerability exists in Mbed TLS versions 3.6.1 through 3.6.3 during the removal of PKCS#7 padding for block ciphers. The root cause is a non-constant-time check where the decryption function exits early if the last byte of the plaintext is outside the valid range (0, BLOCKSIZE]. By acting as a decryption oracle and measuring these timing discrepancies, a remote attacker can recover the last byte of each plaintext block. If the attacker controls a portion of the plaintext, this can be extended to recover the entire plaintext. The issue is resolved in Mbed TLS 3.6.4.

Affected products

  • TrustedFirmware Mbed TLS 3.6.1 through 3.6.3

Timeline

  • 2025-06-30: advisory: Vendor security advisory released
  • 2025-07-20: disclosed: CVE published to NVD

References