ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption) via a crafted application packet within a TLS or DTLS session.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade mbedtlsUpgrade mbedtls2Upgrade mbedtls3 | Jul 31, 2018 | Feb 13, 2018 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Feb 13, 2018 |
| Debian | — | Upgrade mbedtls | Mar 17, 2018 | Feb 13, 2018 |
| Freebsd | — | Upgrade mbedtlsUpgrade polarssl13 | Mar 11, 2018 | Mar 10, 2018 |
| Gentoo Linux | — | Upgrade net-libs/mbedtls. | Apr 23, 2018 | Feb 13, 2018 |
| Suse | — | Upgrade libmbedtls9Upgrade mbedtls-devel | Feb 21, 2018 | Feb 13, 2018 |
| Ubuntu | — | Upgrade libmbedx509-0Upgrade libmbedtls10Upgrade libmbedcrypto0 | Feb 6, 2020 | Feb 13, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub