An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before 1.3.19, 2.x before 2.1.7, and 2.4.x before 2.4.2. A specially crafted x509 certificate, when parsed by mbed TLS library, can cause an invalid free of a stack pointer leading to a potential remote code execution. In order to exploit this vulnerability, an attacker can act as either a client or a server on a network to deliver malicious x509 certificates to vulnerable applications.
CVSS Details
- CVSS 3.0 Base Score: 8.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-mbedtlsalpine-linux-upgrade-mbedtls2alpine-linux-upgrade-mbedtls3 | Aug 22, 2024 | Apr 20, 2017 | |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Apr 20, 2017 | |
| Debian | debian-upgrade-mbedtls | Jul 30, 2024 | Apr 20, 2017 | |
| Gentoo Linux | gentoo-linux-upgrade-net-libs-mbedtls | Oct 30, 2017 | Apr 20, 2017 | |
| Suse | — | suse-upgrade-libmbedtls9suse-upgrade-mbedtls-devel | Mar 23, 2017 | Mar 22, 2017 |
| Ubuntu | ubuntu-upgrade-mbedtls | Nov 19, 2024 | Apr 20, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub