Junglewise Threat Intelligence

CVE-2026-25833: Mbed TLS buffer underflow in x509_inet_pton_ipv6

CVE-2026-25833 · Severity: high · CVSS 7.5 · Published 2026-04-01

Vendors: TrustedFirmware.

Executive brief

Mbed TLS, a widely used open-source cryptographic library for embedded devices, contains a flaw in how it processes certain network addresses in digital certificates. An attacker could potentially exploit this to cause a system crash or service outage. This issue primarily affects systems where the library's built-in address parsing is used instead of the operating system's native functions.

Technical details

A buffer underflow (specifically a buffer underread) exists in the x509_inet_pton_ipv6() function within Mbed TLS. The vulnerability is triggered when the library uses its internal implementation of inet_pton() (typically when the AF_INET6 macro is undefined by the toolchain). When parsing IPv4-mapped IPv6 addresses, a logic error allows the pointer to walk back up to 4 bytes before the start of the buffer. While primarily a memory underread, this can lead to a Denial of Service (DoS) on platforms with strict memory protection if the read crosses a page boundary. The issue is fixed in versions 3.6.6 and 4.1.0.

Affected products

  • TrustedFirmware Mbed TLS 3.5.0 to 3.6.5, 4.0.0

Timeline

  • 2026-03-31: advisory: Vendor advisory published
  • 2026-04-01: disclosed: CVE published to NVD

References