CVEs (73)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Arm Trustedfirmware2Mbed Tls Mbed TlsJul 24, 2026 Apr 2, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who can modify the serialized structures to...Show more |
An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation of the multipart CCM...Show more |
2Arm Trustedfirmware2Mbed Tls Mbed TlsJun 17, 2026 Apr 1, 2026 N/A· v4 9.1 CRITICAL· v3 N/A· v2 An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session. |
An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other par...Show more |
In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected. |
An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0. |
2Arm Trustedfirmware3Mbed Tls Tf Psa CryptoTf Psa CryptoJun 17, 2026 Apr 1, 2026 N/A· v4 6.7 MEDIUM· v3 N/A· v2 An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG). |
3Arm LinaroTrustedfirmware5Mbed Tls Mbed TlsTf Psa Crypto+2 moreJun 17, 2026 Apr 1, 2026 N/A· v4 7.7 HIGH· v3 N/A· v2 Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG). |
Mbed TLS 3.5.0 to 3.6.5 fixed in 3.6.6 and 4.1.0 has a buffer overflow in the x509_inet_pton_ipv6() function |
2Arm Trustedfirmware4Mbed Tls Mbed TlsTf Psa Crypto+1 moreJun 17, 2026 Apr 1, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys. |
2Arm Trustedfirmware2Mbed Tls Mbed TlsJun 17, 2026 Apr 1, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade. |
Mbed TLS through 3.6.4 has an Observable Timing Discrepancy. |
Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_inv or mbedtls_mpi_gcd. |
In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing discrepancy in block cipher padding removal allows an attacker to recover the plaintext when PKCS#7 padding mode is used. |
Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance with the documentation. The function mbedtls_x509_string_to_names() takes a head argument that is docum...Show more |
Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_asn1_store_named_data can trigger conflicting data with val.p of NULL but val.len greater than zero. |
Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer underflow, in mbedtls_pem_read_buffer and two mbedtls_pk_parse functions, via untrusted PEM input. |
Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may be able to extract an AES key from a multithreaded program, or perform a GCM forgery. |
2Arm Trustedfirmware2Mbed Tls Mbed TlsJun 17, 2026 Jul 4, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_import_public_key does not check that the input buffer is at least 4 bytes before reading a 32-bit field, allowing a possible out-of-bounds read on truncated input. Specifically...Show more |
2Arm Trustedfirmware2Mbed Tls Mbed TlsJun 17, 2026 Jul 4, 2025 N/A· v4 4.9 MEDIUM· v3 N/A· v2 In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_verify may accept invalid signatures if hash computation fails and internal errors go unchecked, enabling LMS (Leighton-Micali Signature) forgery in a fault scenario. Specifical...Show more |