# Silicon Labs Security Advisory A-00000555 : Mbed TLS vulnerabilities fixed in version 3.6.4 Flags: Security CVSS Severity: Critical CVSS String: Varies ## Product Impact | Product | Impacted Version | Main SDK | Impacted Version | CVE | | --- | --- | --- | --- | --- | | Mbed TLS | 3.6.3 and earlier | GSDK | All released versions | [CVE-2025-47917](https://nvd.nist.gov/vuln/detail/CVE-2025-47917), [CVE-2025-48965](https://nvd.nist.gov/vuln/detail/CVE-2025-48965), [CVE-2025-49087](https://nvd.nist.gov/vuln/detail/CVE-2025-49087), [CVE-2025-49600](https://nvd.nist.gov/vuln/detail/CVE-2025-49600), [CVE-2025-49601](https://nvd.nist.gov/vuln/detail/CVE-2025-49601), [CVE-2025-52497](https://nvd.nist.gov/vuln/detail/CVE-2025-52497) | | Mbed TLS | 3.6.3 and earlier | SiSDK | 2025.6.x and earlier | [CVE-2025-47917](https://nvd.nist.gov/vuln/detail/CVE-2025-47917), [CVE-2025-48965](https://nvd.nist.gov/vuln/detail/CVE-2025-48965), [CVE-2025-49087](https://nvd.nist.gov/vuln/detail/CVE-2025-49087), [CVE-2025-49600](https://nvd.nist.gov/vuln/detail/CVE-2025-49600), [CVE-2025-49601](https://nvd.nist.gov/vuln/detail/CVE-2025-49601), [CVE-2025-52497](https://nvd.nist.gov/vuln/detail/CVE-2025-52497) | ### Source Product Impact Details - EFx32-based ICs and associated modules - SixG301 based ICs and associated modules | Product | Impacted Version | | --- | --- | | EFx32 devices | GSDK version 4.5.0 and earlier, SiSDK version 2025.6.2 and earlier | | SixG301 devices | SiSDK version 2025.6.2 and earlier | ## CVE ID(s) The following CVEs have been published | CVE Number | Description | CVSS Severity | Vector String | | --- | --- | --- | --- | | [CVE-2025-47917](https://nvd.nist.gov/vuln/detail/CVE-2025-47917) | Misleading memory management in mbedtls_x509_string_to_names() | 8.9 | [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:H](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:H) | | [CVE-2025-48965](https://nvd.nist.gov/vuln/detail/CVE-2025-48965) | NULL pointer dereference after using mbedtls_asn1_store_named_data() | 4.0 | [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N)/A: | | [CVE-2025-49087](https://nvd.nist.gov/vuln/detail/CVE-2025-49087) | Timing side-channel in block cipher decryption with PKCS#7 padding | 4.0 | [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N) | | [CVE-2025-49600](https://nvd.nist.gov/vuln/detail/CVE-2025-49600) | Unchecked return value in LMS verification allows signature bypass | 4.9 | [CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N) | | [CVE-2025-49601](https://nvd.nist.gov/vuln/detail/CVE-2025-49601) | Out-of-bounds read in mbedtls_lms_import_public_key() | 4.8 | [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L) | [CVE-2025-52497](https://nvd.nist.gov/vuln/detail/CVE-2025-52497) | Heap buffer under-read when parsing PEM-encrypted material | 4.8 | [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L) | ## Description - Several vulnerabilities are fixed in third-party library, Mbed TLS 3.6.4. Please see the CVEs for details ### Fix/Workaround - Affected users should upgrade to Simplicity SDK Version 2025.12.0 or later - Instructions for [downloading/updating the SDK](https://docs.silabs.com/simplicity-studio-5-users-guide/latest/ss-5-users-guide-about-the-launcher/toolbar#install) and for [upgrading a project](https://docs.silabs.com/simplicity-studio-5-users-guide/latest/ss-5-users-guide-getting-started/project-upgrade-new-gsdk-version) can be found in the Simplicity Studio Users Guide | Product | Fix Version | Bug ID | Release Notes | | --- | --- | --- | --- | | Simplicity SDK | 2025.12.0 | 1430901 | [Simplicity SDK 2025.12.0 Release Notes](https://docs.silabs.com/sisdk-release-notes/2025.12.0/sisdk-release-notes-overview/) | ## Revision History | Rev | Date | Description of Changes | | --- | --- | --- | | 1.0 | 2026-FEB-05 | Initial publication | ## Attribution ## Additional Resources - Security policy: [https://www.silabs.com/security](https://www.silabs.com/security) - Technical support: [https://www.silabs.com/support](https://www.silabs.com/support)