Arm

Mbed Tls

73 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.22%
  • Veröffentlicht 02.04.2026 00:00:00
  • Zuletzt bearbeitet 06.04.2026 21:06:00

An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who can modify the serialized structures to induce memory corruption, lea...

  • EPSS 0.03%
  • Veröffentlicht 02.04.2026 00:00:00
  • Zuletzt bearbeitet 07.04.2026 12:14:22

An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation of the multipart CCM API with an oversized tag_len ...

  • EPSS 0.05%
  • Veröffentlicht 01.04.2026 00:00:00
  • Zuletzt bearbeitet 06.04.2026 14:18:32

Mbed TLS 3.5.0 to 3.6.5 fixed in 3.6.6 and 4.1.0 has a buffer overflow in the x509_inet_pton_ipv6() function

  • EPSS 0.02%
  • Veröffentlicht 01.04.2026 00:00:00
  • Zuletzt bearbeitet 06.04.2026 14:17:14

Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.

  • EPSS 0.06%
  • Veröffentlicht 01.04.2026 00:00:00
  • Zuletzt bearbeitet 06.04.2026 14:18:04

An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.

  • EPSS 0.02%
  • Veröffentlicht 01.04.2026 00:00:00
  • Zuletzt bearbeitet 06.04.2026 14:29:47

Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG).

  • EPSS 0.08%
  • Veröffentlicht 01.04.2026 00:00:00
  • Zuletzt bearbeitet 03.04.2026 20:06:34

An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0.

  • EPSS 0.02%
  • Veröffentlicht 01.04.2026 00:00:00
  • Zuletzt bearbeitet 06.04.2026 14:30:17

An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG).

  • EPSS 0.02%
  • Veröffentlicht 01.04.2026 00:00:00
  • Zuletzt bearbeitet 03.04.2026 20:02:33

An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other party can force the shared secret...

  • EPSS 0.02%
  • Veröffentlicht 01.04.2026 00:00:00
  • Zuletzt bearbeitet 03.04.2026 20:04:38

In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected.