An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before 1.3.19, 2.x before 2.1.7, and 2.4.x before 2.4.2. A specially crafted x509 certificate, when parsed by mbed TLS library, can cause an invalid free of a stack pointer leading to a potential remote code execution. In order to exploit this vulnerability, an attacker can act as either a client or a server on a network to deliver malicious x509 certificates to vulnerable applications.
CVSS Details
- CVSS 3.0 Base Score: 8.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade mbedtlsUpgrade mbedtls3Upgrade mbedtls2 | Aug 22, 2024 | Apr 20, 2017 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Apr 20, 2017 |
| Debian | — | Upgrade mbedtls | Jul 30, 2024 | Apr 20, 2017 |
| Gentoo Linux | — | Upgrade net-libs/mbedtls. | Oct 30, 2017 | Apr 20, 2017 |
| Suse | — | Upgrade mbedtls-develUpgrade libmbedtls9 | Mar 23, 2017 | Mar 22, 2017 |
| Ubuntu | — | Upgrade mbedtls | Nov 19, 2024 | Apr 20, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub