# Silicon Labs Security Advisory A-00000568 : Multiple vulnerabilities in MbedTLS versions from 2.6.12 to 3.6.5 Flags: Security CVSS Severity: Critical CVSS String: Varies ## Product Impact | Product | Impacted Version | Main SDK | Impacted Version | CVE | | --- | --- | --- | --- | --- | | Mbed TLS | 3.0.0 and earlier | GSDK | 4.0.x and earlier | [CVE-2021-44732](https://nvd.nist.gov/vuln/detail/CVE-2021-44732) | | Mbed TLS | 3.4.x and earlier | GSDK | 4.3.x and earlier | [CVE-2021-43615](https://nvd.nist.gov/vuln/detail/CVE-2021-43615) | | Mbed TLS | 3.6.1 and earlier | GSDK | All versions | [CVE-2024-49195](https://nvd.nist.gov/vuln/detail/CVE-2024-49195) | | Mbed TLS | 3.6.4 and earlier | GSDK | All versions | [CVE-2025-59438](https://nvd.nist.gov/vuln/detail/CVE-2025-59438) | | Mbed TLS | 3.6.1 and earlier | SiSDK | 2024.6.x and earlier | [CVE-2024-49195](https://nvd.nist.gov/vuln/detail/CVE-2024-49195) | | Mbed TLS | 3.6.4 and earlier | SiSDK | All versions | [CVE-2025-59438](https://nvd.nist.gov/vuln/detail/CVE-2025-59438) | ### Source Product Impact Details - EFx32-based ICs and associated modules - SixG301-ICs | Product | Impacted Version | | --- | --- | | EFx32 devices | Various GSDK/SiSDK versions are impacted, see the table in Fix/Workaround for the impacted and fixed versions | | SixG301 devices | Various SiSDK versions are impacted, see the table in Fix/Workaround for the impacted and fixed versions | ## CVE ID(s) - The following CVEs have been published CVSS | CVE Number | Description | Vector String | | --- | --- | --- | | [CVE-2021-44732](https://nvd.nist.gov/vuln/detail/CVE-2021-44732) | Double free in certain out-of-9.8 memory conditions | [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) | | [CVE-2021-43615](https://nvd.nist.gov/vuln/detail/CVE-2021-43615) | Buffer overread in TLS stream 7.5 cipher suites | [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) | | [CVE-2024-30166](https://nvd.nist.gov/vuln/detail/CVE-2024-30166) | Stack buffer over read in TLS 1.3 9.1 server | [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H) | | [CVE-2024-45158](https://nvd.nist.gov/vuln/detail/CVE-2024-45158) | Stack buffer overflow in ECDSA 9.8 signature conversion functions | [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) | | [CVE-2024-49195](https://nvd.nist.gov/vuln/detail/CVE-2024-49195) | Buffer underrun in pkwrite when 9.8 writing an opaque key pair | [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) | | [CVE-2025-54764](https://nvd.nist.gov/vuln/detail/CVE-2025-54764) | Side channel in RSA key 6.2 generation and operations | [CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) | | [CVE-2025-59438](https://nvd.nist.gov/vuln/detail/CVE-2025-59438) | Padding oracle through timing of 5.3 cipher error reporting | [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) | ## Description - This advisory covers the vulnerabilities that are fixed in third-party library Mbed TLS, 2.6.12 to 3.6.5, which were not addressed earlier. Please see the CVEs for details. - The vulnerability in [CVE-2024-30166](https://nvd.nist.gov/vuln/detail/CVE-2024-30166) does NOT impact GSDK or SiSDK. - GSDK does not support TLS 1.3 servers. - The versions of SiSDK that use vulnerable versions of mbedtls do not support TLS 1.3 servers. - The vulnerability in [CVE-2024-45158](https://nvd.nist.gov/vuln/detail/CVE-2024-45158) does NOT impact GSDK or SiSDK. - GSDK does not use the impacted functions. - The versions of SiSDK that use vulnerable versions of mbedtls do not support the impacted functions. - The vulnerability in [CVE-2025-54764](https://nvd.nist.gov/vuln/detail/CVE-2025-54764) does NOT impact GSDK or SiSDK. It relates to RSA, which is not supported through mbedtls in either SDK. ### Fix/Workaround - Affected users should upgrade to following SiSDK or GSDK versions (or newer versions) as shown below - Instructions for downloading/updating the SDK and for upgrading a project can be found in the Simplicity Studio Users Guide | CVE ID | Mbed TLS Fix Version | Product | Fix Version | Release Notes | | --- | --- | --- | --- | --- | | [CVE-2021-44732](https://nvd.nist.gov/vuln/detail/CVE-2021-44732) | 3.0.1 | Gecko SDK | 4.1.0 | [Gecko SDK 4.1](https://www.silabs.com/documents/public/release-notes/gecko-platform-release-notes-4.1.6.0.pdf) | | [CVE-2021-43615](https://nvd.nist.gov/vuln/detail/CVE-2021-43615) | 3.5.0 | Gecko SDK | 4.4.0 | [Gecko SDK 4.4](https://www.silabs.com/documents/public/release-notes/gecko-platform-release-notes-4.4.4.0.pdf) | | [CVE-2024-49195](https://nvd.nist.gov/vuln/detail/CVE-2024-49195) | 3.6.2 | Currently there is no plan to fix these CVEs in Gecko SDK. Please refer to Mbed TLS advisory for more details | | | [CVE-2025-59438](https://nvd.nist.gov/vuln/detail/CVE-2025-59438) | 3.6.5 | Currently there is no plan to fix these CVEs in Gecko SDK. Please refer to Mbed TLS advisory for more details | | | | CVE ID | Mbed TLS Fix Version | Product | Fix Version | Release Notes | | --- | --- | --- | --- | --- | | [CVE-2021-44732](https://nvd.nist.gov/vuln/detail/CVE-2021-44732) | 3.0.1 | Simplicity SDK | 2024.6.0 | [SiSDK 2024.6.0](https://www.silabs.com/documents/public/release-notes/gecko-platform-release-notes-5.0.0.0.pdf) | | [CVE-2021-43615](https://nvd.nist.gov/vuln/detail/CVE-2021-43615) | 3.5.0 | Simplicity SDK | 2024.6.0 | [SiSDK 2024.6.0](https://www.silabs.com/documents/public/release-notes/gecko-platform-release-notes-5.0.0.0.pdf) | | [CVE-2024-49195](https://nvd.nist.gov/vuln/detail/CVE-2024-49195) | 3.6.2 | Simplicity SDK | 2024.12.0 | [SiSDK 2024.12.0](https://www.silabs.com/documents/public/release-notes/gecko-platform-release-notes-5.1.0.0.pdf) | | [CVE-2025-59438](https://nvd.nist.gov/vuln/detail/CVE-2025-59438) | 3.6.5 | Currently Simplicity SDK has no fix for these CVEs. Please refer to Mbed TLS advisory for more details. | | ## Revision History | Rev | Date | Description of Changes | | --- | --- | --- | | 3.0 | 2026-AUG-13 | Updated impact of CVE-2024-30166 | | 2.0 | 2026-MAY-12 | Updated fix version for CVE-2021-44732 | | | | Updated impact of CVE-2024-45158 and CVE-2025-54764 | | 1.0 | 2026-MAR-19 | Initial publication | ## Attribution ## Additional Resources - Security policy: [https://www.silabs.com/security](https://www.silabs.com/security) - Technical support: [https://www.silabs.com/support](https://www.silabs.com/support)