Debian Mbedtls vulnerabilities
48 known vulnerabilities affecting debian/mbedtls.
Total CVEs
48
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH14MEDIUM23LOW5
Vulnerabilities
Page 1 of 3
CVE-2025-47917P2HIGHCVSS 8.9PoCfixed in mbedtls 2.16.9-0.1+deb11u3 (bullseye)2025
CVE-2025-47917 [HIGH] CVE-2025-47917: mbedtls - Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applicati...
Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance with the documentation. The function mbedtls_x509_string_to_names() takes a head argument that is documented as an output argument. The documentation does not suggest that the function will free that pointer; however, the function does call mbedtls_as
debian
CVE-2018-0487P3CRITICALCVSS 9.8fixed in mbedtls 2.7.0-2 (bookworm)2018
CVE-2018-0487 [CRITICAL] CVE-2018-0487: mbedtls - ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0 allows remote attack...
ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via a crafted certificate chain that is mishandled during RSASSA-PSS signature verification within a TLS or DTLS session.
Scope: local
bookworm: resolved (fixed in 2.7.0-2)
bullseye: resolved (fixed in 2.7.0-2
debian
CVE-2022-35409P3CRITICALCVSS 9.1fixed in mbedtls 2.28.1-1 (bookworm)2022
CVE-2022-35409 [CRITICAL] CVE-2022-35409: mbedtls - An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0. In some ...
An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0. In some configurations, an unauthenticated attacker can send an invalid ClientHello message to a DTLS server that causes a heap-based buffer over-read of up to 255 bytes. This can cause a server crash or possibly information disclosure based on error responses. Affected configurations have M
debian
CVE-2018-0488P3CRITICALCVSS 9.8fixed in mbedtls 2.7.0-2 (bookworm)2018
CVE-2018-0488 [CRITICAL] CVE-2018-0488: mbedtls - ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated ...
ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption) via a crafted application packet within a TLS or DTLS session.
Scope: local
bookworm: resolved (fixed in 2.7.0-2)
bullseye: resolved (fixed in 2.7.0-2)
fork
debian
CVE-2017-14032P3HIGHCVSS 8.1fixed in mbedtls 2.6.0-1 (bookworm)2017
CVE-2017-14032 [HIGH] CVE-2017-14032: mbedtls - ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is c...
ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentication via an X.509 certificate chain with many intermediates. NOTE: although mbed TLS was formerly known as PolarSSL, the releases shipped with the PolarSSL name are not affected.
Scope: local
bookworm: resolved (fixed in 2.6.0-1
debian
CVE-2017-2784P3HIGHCVSS 8.1fixed in mbedtls 2.4.2-1 (bookworm)2017
CVE-2017-2784 [HIGH] CVE-2017-2784: mbedtls - An exploitable free of a stack pointer vulnerability exists in the x509 certific...
An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before 1.3.19, 2.x before 2.1.7, and 2.4.x before 2.4.2. A specially crafted x509 certificate, when parsed by mbed TLS library, can cause an invalid free of a stack pointer leading to a potential remote code execution. In order to exploit this vulnerability
debian
CVE-2024-49195P3LOWCVSS 9.8fixed in mbedtls 3.6.2-1 (forky)2024
CVE-2024-49195 [CRITICAL] CVE-2024-49195: mbedtls - Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when ...
Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pair
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 3.6.2-1)
sid: resolved (fixed in 3.6.2-1)
trixie: resolved (fixed in 3.6.2-1)
debian
CVE-2017-18187P3CRITICALCVSS 9.8fixed in mbedtls 2.7.0-2 (bookworm)2017
CVE-2017-18187 [CRITICAL] CVE-2017-18187: mbedtls - In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through an integer ...
In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through an integer overflow in PSK identity parsing in the ssl_parse_client_psk_identity() function in library/ssl_srv.c.
Scope: local
bookworm: resolved (fixed in 2.7.0-2)
bullseye: resolved (fixed in 2.7.0-2)
forky: resolved (fixed in 2.7.0-2)
sid: resolved (fixed in 2.7.0-2)
trixie: resolved (fixed
debian
CVE-2021-44732P3CRITICALCVSS 9.8fixed in mbedtls 2.28.0-0.3 (bookworm)2021
CVE-2021-44732 [CRITICAL] CVE-2021-44732: mbedtls - Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as ...
Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.
Scope: local
bookworm: resolved (fixed in 2.28.0-0.3)
bullseye: resolved (fixed in 2.16.9-0.1+deb11u1)
forky: resolved (fixed in 2.28.0-0.3)
sid: resolved (fixed in 2.28.0-0.3)
trixie: resolved (fixed in 2.28.0-0.3)
debian
CVE-2022-46393P3CRITICALCVSS 9.8fixed in mbedtls 2.28.2-1 (bookworm)2022
CVE-2022-46393 [CRITICAL] CVE-2022-46393: mbedtls - An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is...
An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow and heap-based buffer over-read in DTLS if MBEDTLS_SSL_DTLS_CONNECTION_ID is enabled and MBEDTLS_SSL_CID_IN_LEN_MAX > 2 * MBEDTLS_SSL_CID_OUT_LEN_MAX.
Scope: local
bookworm: resolved (fixed in 2.28.2-1)
bullseye: resolved
forky: resolved (fixed
debian
CVE-2020-36423P3HIGHCVSS 7.5fixed in mbedtls 2.16.9-0.1 (bookworm)2020
CVE-2020-36423 [HIGH] CVE-2020-36423: mbedtls - An issue was discovered in Arm Mbed TLS before 2.23.0. A remote attacker can rec...
An issue was discovered in Arm Mbed TLS before 2.23.0. A remote attacker can recover plaintext because a certain Lucky 13 countermeasure doesn't properly consider the case of a hardware accelerator.
Scope: local
bookworm: resolved (fixed in 2.16.9-0.1)
bullseye: resolved (fixed in 2.16.9-0.1)
forky: resolved (fixed in 2.16.9-0.1)
sid: resolved (fixed in 2.16.9-0.1)
debian
CVE-2025-52496P3HIGHCVSS 7.8fixed in mbedtls 2.16.9-0.1+deb11u2 (bullseye)2025
CVE-2025-52496 [HIGH] CVE-2025-52496: mbedtls - Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compile...
Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may be able to extract an AES key from a multithreaded program, or perform a GCM forgery.
Scope: local
bookworm: open
bullseye: resolved (fixed in 2.16.9-0.1+deb11u2)
forky: resolved (fixed in 3.6.4-1)
sid: resolved (fixed in 3.6.4-1)
trixie: resolved (
debian
CVE-2024-28960P3HIGHCVSS 8.2fixed in mbedtls 2.28.8-1 (forky)2024
CVE-2024-28960 [HIGH] CVE-2024-28960: mbedtls - An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x ...
An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.28.8-1)
sid: resolved (fixed in 2.28.8-1)
trixie: resolved (fixed in 2.28.8-1)
debian
CVE-2020-36476P3HIGHCVSS 7.5fixed in mbedtls 2.16.9-0.1 (bookworm)2020
CVE-2020-36476 [HIGH] CVE-2020-36476: mbedtls - An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and bef...
An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS). There is missing zeroization of plaintext buffers in mbedtls_ssl_read to erase unused application data from memory.
Scope: local
bookworm: resolved (fixed in 2.16.9-0.1)
bullseye: resolved (fixed in 2.16.9-0.1)
forky: resolved (fixed in 2.16.9-0.1)
sid: resolved (fixed i
debian
CVE-2020-36475P3HIGHCVSS 7.5fixed in mbedtls 2.16.9-0.1 (bookworm)2020
CVE-2020-36475 [HIGH] CVE-2020-36475: mbedtls - An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and bef...
An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). The calculations performed by mbedtls_mpi_exp_mod are not limited; thus, supplying overly large parameters could lead to denial of service when generating Diffie-Hellman key pairs.
Scope: local
bookworm: resolved (fixed in 2.16.9-0.1)
bullseye: resolved (fixed in 2.16.9-
debian
CVE-2021-43666P3HIGHCVSS 7.5fixed in mbedtls 2.28.0-1 (bookworm)2021
CVE-2021-43666 [HIGH] CVE-2021-43666: mbedtls - A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mb...
A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an input password's length is 0.
Scope: local
bookworm: resolved (fixed in 2.28.0-1)
bullseye: resolved (fixed in 2.16.9-0.1+deb11u1)
forky: resolved (fixed in 2.28.0-1)
sid: resolved (fixed in 2.28.0-1)
trixie: resolved (fixed in 2.28.0-1)
debian
CVE-2020-36426P3HIGHCVSS 7.5fixed in mbedtls 2.16.9-0.1 (bookworm)2020
CVE-2020-36426 [HIGH] CVE-2020-36426: mbedtls - An issue was discovered in Arm Mbed TLS before 2.24.0. mbedtls_x509_crl_parse_de...
An issue was discovered in Arm Mbed TLS before 2.24.0. mbedtls_x509_crl_parse_der has a buffer over-read (of one byte).
Scope: local
bookworm: resolved (fixed in 2.16.9-0.1)
bullseye: resolved (fixed in 2.16.9-0.1)
forky: resolved (fixed in 2.16.9-0.1)
sid: resolved (fixed in 2.16.9-0.1)
trixie: resolved (fixed in 2.16.9-0.1)
debian
CVE-2020-36478P3HIGHCVSS 7.5fixed in mbedtls 2.16.9-0.1 (bookworm)2020
CVE-2020-36478 [HIGH] CVE-2020-36478: mbedtls - An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and bef...
An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certificate is considered valid. However, if the parameters do not match in any way, then the certificate should be considered invalid.
Scope: local
bookworm: resolved (fixed i
debian
CVE-2025-48965P3MEDIUMCVSS 4.0fixed in mbedtls 2.16.9-0.1+deb11u2 (bullseye)2025
CVE-2025-48965 [MEDIUM] CVE-2025-48965: mbedtls - Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_asn1_store_...
Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_asn1_store_named_data can trigger conflicting data with val.p of NULL but val.len greater than zero.
Scope: local
bookworm: open
bullseye: resolved (fixed in 2.16.9-0.1+deb11u2)
forky: resolved (fixed in 3.6.4-1)
sid: resolved (fixed in 3.6.4-1)
trixie: resolved (fixed in 3.6.4-1)
debian
CVE-2018-9989P4HIGHCVSS 7.5fixed in mbedtls 2.8.0-1 (bookworm)2018
CVE-2018-9989 [HIGH] CVE-2018-9989: mbedtls - ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-rea...
ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_psk_hint() that could cause a crash on invalid input.
Scope: local
bookworm: resolved (fixed in 2.8.0-1)
bullseye: resolved (fixed in 2.8.0-1)
forky: resolved (fixed in 2.8.0-1)
sid: resolved (fixed in 2.8.0-1)
trixie: resolved (fixed in 2.8.0-1)
debian
1 / 3Next →