cbcvebase.

Debian Mbedtls vulnerabilities

48 known vulnerabilities affecting debian/mbedtls.

Total CVEs
48
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH14MEDIUM23LOW5

Vulnerabilities

Page 3 of 3
CVE-2020-10932P4MEDIUMCVSS 4.7fixed in mbedtls 2.16.9-0.1 (bookworm)2020
CVE-2020-10932 [MEDIUM] CVE-2020-10932: mbedtls - An issue was discovered in Arm Mbed TLS before 2.16.6 and 2.7.x before 2.7.15. A... An issue was discovered in Arm Mbed TLS before 2.16.6 and 2.7.x before 2.7.15. An attacker that can get precise enough side-channel measurements can recover the long-term ECDSA private key by (1) reconstructing the projective coordinate of the result of scalar multiplication by exploiting side channels in the conversion to affine coordinates; (2) using an attack d
debian
CVE-2021-36647P4MEDIUMCVSS 4.7fixed in mbedtls 2.16.11-0.1 (bookworm)2021
CVE-2021-36647 [MEDIUM] CVE-2021-36647: mbedtls - Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp... Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS all versions before 3.0.0, 2.27.0 or 2.16.11 allows attackers with access to precise enough timing and memory access information (typically an untrusted operating system attacking a secure enclave such as SGX or the TrustZone secure world) to rec
debian
CVE-2025-49600P4LOWCVSS 4.9fixed in mbedtls 3.6.4-1 (forky)2025
CVE-2025-49600 [MEDIUM] CVE-2025-49600: mbedtls - In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_verify may accept invalid signatures ... In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_verify may accept invalid signatures if hash computation fails and internal errors go unchecked, enabling LMS (Leighton-Micali Signature) forgery in a fault scenario. Specifically, unchecked return values in mbedtls_lms_verify allow an attacker (who can induce a hardware hash accelerator fault) to bypass LMS signature ver
debian
CVE-2018-0498P4MEDIUMCVSS 4.7fixed in mbedtls 2.12.0-1 (bookworm)2018
CVE-2018-0498 [MEDIUM] CVE-2018-0498: mbedtls - ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows local users t... ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows local users to achieve partial plaintext recovery (for a CBC based ciphersuite) via a cache-based side-channel attack. Scope: local bookworm: resolved (fixed in 2.12.0-1) bullseye: resolved (fixed in 2.12.0-1) forky: resolved (fixed in 2.12.0-1) sid: resolved (fixed in 2.12.0-1) trixie: resolved (fix
debian
CVE-2020-36424P4MEDIUMCVSS 4.7fixed in mbedtls 2.16.9-0.1 (bookworm)2020
CVE-2020-36424 [MEDIUM] CVE-2020-36424: mbedtls - An issue was discovered in Arm Mbed TLS before 2.24.0. An attacker can recover a... An issue was discovered in Arm Mbed TLS before 2.24.0. An attacker can recover a private key (for RSA or static Diffie-Hellman) via a side-channel attack against generation of base blinding/unblinding values. Scope: local bookworm: resolved (fixed in 2.16.9-0.1) bullseye: resolved (fixed in 2.16.9-0.1) forky: resolved (fixed in 2.16.9-0.1) sid: resolved (fixed in
debian
CVE-2019-18222P4MEDIUMCVSS 4.7fixed in mbedtls 2.16.4-1 (bookworm)2019
CVE-2019-18222 [MEDIUM] CVE-2019-18222: mbedtls - The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TL... The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to recover the private key via side-channel attacks. Scope: local bookworm: resolved (fixed in 2.16.4-1) bullseye: resolved (fixed in 2.16.4-1) forky: resolved (fixed in 2.16
debian
CVE-2018-19608P4MEDIUMCVSS 4.7fixed in mbedtls 2.14.1-1 (bookworm)2018
CVE-2018-19608 [MEDIUM] CVE-2018-19608: mbedtls - Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unpri... Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites. Scope: local bookworm: resolved (fixed in 2.14.1-1) bullseye: resolved (fixed in 2.14.1-1) forky: resolved (fixed in 2.14.1-1) sid: resolved (fixed in 2.14.1-1) trixie: re
debian
CVE-2025-49087P4LOWCVSS 4.0fixed in mbedtls 3.6.4-1 (forky)2025
CVE-2025-49087 [MEDIUM] CVE-2025-49087: mbedtls - In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing discrepancy in block ciph... In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing discrepancy in block cipher padding removal allows an attacker to recover the plaintext when PKCS#7 padding mode is used. Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 3.6.4-1) sid: resolved (fixed in 3.6.4-1) trixie: resolved (fixed in 3.6.4-1)
debian
Debian Mbedtls vulnerabilities | cvebase