ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption) via a crafted application packet within a TLS or DTLS session.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade mbedtls3Upgrade mbedtls2Upgrade mbedtls | Jul 31, 2018 | Feb 13, 2018 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Feb 13, 2018 |
| Debian | — | Upgrade mbedtls | Mar 17, 2018 | Feb 13, 2018 |
| Freebsd | — | Upgrade mbedtlsUpgrade polarssl13 | Mar 11, 2018 | Mar 10, 2018 |
| Gentoo Linux | — | Upgrade net-libs/mbedtls. | Apr 23, 2018 | Feb 13, 2018 |
| Suse | — | Upgrade mbedtls-develUpgrade libmbedtls9 | Feb 21, 2018 | Feb 13, 2018 |
| Ubuntu | — | Upgrade libmbedcrypto0Upgrade libmbedtls10Upgrade libmbedx509-0 | Feb 6, 2020 | Feb 13, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub