MEDIUM 5.4 Microsoft
CVE-2025-27810
Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.
Microsoft Security Update 2025-Mar: Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.
Affected Products
- cbl2 qemu 6.2.0-24 on CBL Mariner 2.0
- azl3 qemu 8.2.0-16 on Azure Linux 3.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27810
- https://nvd.nist.gov/vuln/detail/CVE-2025-27810
This medium severity vulnerability with a CVSS score of 5.4 was published on 2025-03-11 via Microsoft. Affected: cbl2 qemu 6.2.0-24 on CBL Mariner 2.0, azl3 qemu 8.2.0-16 on Azure Linux 3.0.
vulnfeed aggregates 8893 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.