Debian Mbedtls vulnerabilities
48 known vulnerabilities affecting debian/mbedtls.
Total CVEs
48
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH14MEDIUM23LOW5
Vulnerabilities
Page 2 of 3
CVE-2018-9988P4HIGHCVSS 7.5fixed in mbedtls 2.8.0-1 (bookworm)2018
CVE-2018-9988 [HIGH] CVE-2018-9988: mbedtls - ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-rea...
ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_key_exchange() that could cause a crash on invalid input.
Scope: local
bookworm: resolved (fixed in 2.8.0-1)
bullseye: resolved (fixed in 2.8.0-1)
forky: resolved (fixed in 2.8.0-1)
sid: resolved (fixed in 2.8.0-1)
trixie: resolved (fixed in 2.8.0-1)
debian
CVE-2024-23775P4HIGHCVSS 7.5fixed in mbedtls 2.28.7-1 (forky)2024
CVE-2024-23775 [HIGH] CVE-2024-23775: mbedtls - Integer Overflow vulnerability in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5....
Integer Overflow vulnerability in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2, allows attackers to cause a denial of service (DoS) via mbedtls_x509_set_extension().
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.28.7-1)
sid: resolved (fixed in 2.28.7-1)
trixie: resolved (fixed in 2.28.7-1)
debian
CVE-2025-49601P3LOWCVSS 4.8fixed in mbedtls 3.6.4-1 (forky)2025
CVE-2025-49601 [MEDIUM] CVE-2025-49601: mbedtls - In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_import_public_key does not check that...
In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_import_public_key does not check that the input buffer is at least 4 bytes before reading a 32-bit field, allowing a possible out-of-bounds read on truncated input. Specifically, an out-of-bounds read in mbedtls_lms_import_public_key allows context-dependent attackers to trigger a crash or limited adjacent-memory disclosu
debian
CVE-2024-28755P4MEDIUMCVSS 6.5fixed in mbedtls 3.6.0-3 (forky)2024
CVE-2024-28755 [MEDIUM] CVE-2024-28755: mbedtls - An issue was discovered in Mbed TLS 3.5.x before 3.6.0. When an SSL context was ...
An issue was discovered in Mbed TLS 3.5.x before 3.6.0. When an SSL context was reset with the mbedtls_ssl_session_reset() API, the maximum TLS version to be negotiated was not restored to the configured one. An attacker was able to prevent an Mbed TLS server from establishing any TLS 1.3 connection, potentially resulting in a Denial of Service or forced version d
debian
CVE-2018-0497P4LOWCVSS 2.6fixed in mbedtls 2.12.0-1 (bookworm)2018
CVE-2018-0497 [LOW] CVE-2018-0497: mbedtls - ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows remote attack...
ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows remote attackers to achieve partial plaintext recovery (for a CBC based ciphersuite) via a timing-based side-channel attack. This vulnerability exists because of an incorrect fix (with a wrong SHA-384 calculation) for CVE-2013-0169.
Scope: local
bookworm: resolved (fixed in 2.12.0-1)
bullseye: resolved
debian
CVE-2020-36477P4MEDIUMCVSS 5.9fixed in mbedtls 2.28.0-0.3 (bookworm)2020
CVE-2020-36477 [MEDIUM] CVE-2020-36477: mbedtls - An issue was discovered in Mbed TLS before 2.24.0. The verification of X.509 cer...
An issue was discovered in Mbed TLS before 2.24.0. The verification of X.509 certificates when matching the expected common name (the cn argument of mbedtls_x509_crt_verify) with the actual certificate name is mishandled: when the subjecAltName extension is present, the expected name is compared to any name in that extension regardless of its type. This means that
debian
CVE-2019-16910P4MEDIUMCVSS 5.3fixed in mbedtls 2.16.3-1 (bookworm)2019
CVE-2019-16910 [MEDIUM] CVE-2019-16910: mbedtls - Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ...
Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insufficient entropy for blinding, which might allow an attacker to recover a private key via side-channel attacks if a victim signs the same message many times. (For Mbed TLS, the fix is also available in versions 2.7.12 and 2.16.3.)
Scope: local
book
debian
CVE-2025-27809P4MEDIUMCVSS 5.4fixed in mbedtls 3.6.3-1 (forky)2025
CVE-2025-27809 [MEDIUM] CVE-2025-27809: mbedtls - Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts server...
Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 3.6.3-1)
sid: resolved (fixed in 3.6.3-1)
trixie: resolved (fixed in 3.6.3-1)
debian
CVE-2020-10941P4MEDIUMCVSS 5.9fixed in mbedtls 2.16.5-1 (bookworm)2020
CVE-2020-10941 [MEDIUM] CVE-2020-10941: mbedtls - Arm Mbed TLS before 2.16.5 allows attackers to obtain sensitive information (an ...
Arm Mbed TLS before 2.16.5 allows attackers to obtain sensitive information (an RSA private key) by measuring cache usage during an import.
Scope: local
bookworm: resolved (fixed in 2.16.5-1)
bullseye: resolved (fixed in 2.16.5-1)
forky: resolved (fixed in 2.16.5-1)
sid: resolved (fixed in 2.16.5-1)
trixie: resolved (fixed in 2.16.5-1)
debian
CVE-2020-36421P4MEDIUMCVSS 5.3fixed in mbedtls 2.16.9-0.1 (bookworm)2020
CVE-2020-36421 [MEDIUM] CVE-2020-36421: mbedtls - An issue was discovered in Arm Mbed TLS before 2.23.0. Because of a side channel...
An issue was discovered in Arm Mbed TLS before 2.23.0. Because of a side channel in modular exponentiation, an RSA private key used in a secure enclave could be disclosed.
Scope: local
bookworm: resolved (fixed in 2.16.9-0.1)
bullseye: resolved (fixed in 2.16.9-0.1)
forky: resolved (fixed in 2.16.9-0.1)
sid: resolved (fixed in 2.16.9-0.1)
trixie: resolved (fixed i
debian
CVE-2020-36425P4MEDIUMCVSS 5.3fixed in mbedtls 2.16.9-0.1 (bookworm)2020
CVE-2020-36425 [MEDIUM] CVE-2020-36425: mbedtls - An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a rev...
An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocation via a CRL. In some situations, an attacker can exploit this by changing the local clock.
Scope: local
bookworm: resolved (fixed in 2.16.9-0.1)
bullseye: resolved (fixed in 2.16.9-0.1)
forky: resolved (fixed in 2.16
debian
CVE-2025-54764P4MEDIUMCVSS 6.2fixed in mbedtls 3.6.5-0.1 (forky)2025
CVE-2025-54764 [MEDIUM] CVE-2025-54764: mbedtls - Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operation...
Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_inv or mbedtls_mpi_gcd.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 3.6.5-0.1)
sid: resolved (fixed in 3.6.5-0.1)
trixie: resolved (fixed in 3.6.5-0.1~deb13u1)
debian
CVE-2020-36422P4MEDIUMCVSS 5.3fixed in mbedtls 2.16.9-0.1 (bookworm)2020
CVE-2020-36422 [MEDIUM] CVE-2020-36422: mbedtls - An issue was discovered in Arm Mbed TLS before 2.23.0. A side channel allows rec...
An issue was discovered in Arm Mbed TLS before 2.23.0. A side channel allows recovery of an ECC private key, related to mbedtls_ecp_check_pub_priv, mbedtls_pk_parse_key, mbedtls_pk_parse_keyfile, mbedtls_ecp_mul, and mbedtls_ecp_mul_restartable.
Scope: local
bookworm: resolved (fixed in 2.16.9-0.1)
bullseye: resolved (fixed in 2.16.9-0.1)
forky: resolved (fixed in
debian
CVE-2022-46392P4MEDIUMCVSS 5.3fixed in mbedtls 2.28.2-1 (bookworm)2022
CVE-2022-46392 [MEDIUM] CVE-2022-46392: mbedtls - An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adver...
An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough information about memory accesses (typically, an untrusted operating system attacking a secure enclave) can recover an RSA private key after observing the victim performing a single private-key operation, if the window size (MBEDTLS_MPI_WINDOW_SIZE) u
debian
CVE-2025-59438P4MEDIUMCVSS 5.3fixed in mbedtls 3.6.5-0.1 (forky)2025
CVE-2025-59438 [MEDIUM] CVE-2025-59438: mbedtls - Mbed TLS through 3.6.4 has an Observable Timing Discrepancy.
Mbed TLS through 3.6.4 has an Observable Timing Discrepancy.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 3.6.5-0.1)
sid: resolved (fixed in 3.6.5-0.1)
trixie: resolved (fixed in 3.6.5-0.1~deb13u1)
debian
CVE-2020-16150P4MEDIUMCVSS 5.5fixed in mbedtls 2.16.9-0.1 (bookworm)2020
CVE-2020-16150 [MEDIUM] CVE-2020-16150: mbedtls - A Lucky 13 timing side channel in mbedtls_ssl_decrypt_buf in library/ssl_msg.c i...
A Lucky 13 timing side channel in mbedtls_ssl_decrypt_buf in library/ssl_msg.c in Trusted Firmware Mbed TLS through 2.23.0 allows an attacker to recover secret key information. This affects CBC mode because of a computed time difference based on a padding length.
Scope: local
bookworm: resolved (fixed in 2.16.9-0.1)
bullseye: resolved (fixed in 2.16.9-0.1)
forky:
debian
CVE-2024-23170P4MEDIUMCVSS 5.5fixed in mbedtls 2.28.7-1 (forky)2024
CVE-2024-23170 [MEDIUM] CVE-2024-23170: mbedtls - An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. Ther...
An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations. This side channel could be sufficient for a local attacker to recover the plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario
debian
CVE-2021-24119P4MEDIUMCVSS 4.9fixed in mbedtls 2.16.11-0.1 (bookworm)2021
CVE-2021-24119 [MEDIUM] CVE-2021-24119: mbedtls - In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM ...
In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments that can be single stepped, especially Intel SGX.
Scope: local
bookworm: resolved (fixed
debian
CVE-2025-27810P4MEDIUMCVSS 5.4fixed in mbedtls 3.6.3-1 (forky)2025
CVE-2025-27810 [MEDIUM] CVE-2025-27810: mbedtls - Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory all...
Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 3.6.3-1)
sid: resolved (fixed in 3.6.3-1)
trixie: resolv
debian
CVE-2025-52497P4MEDIUMCVSS 4.8fixed in mbedtls 2.16.9-0.1+deb11u2 (bullseye)2025
CVE-2025-52497 [MEDIUM] CVE-2025-52497: mbedtls - Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer underflow, in...
Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer underflow, in mbedtls_pem_read_buffer and two mbedtls_pk_parse functions, via untrusted PEM input.
Scope: local
bookworm: open
bullseye: resolved (fixed in 2.16.9-0.1+deb11u2)
forky: resolved (fixed in 3.6.4-1)
sid: resolved (fixed in 3.6.4-1)
trixie: resolved (fixed in 3.6.4-1)
debian