CVEs (73)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Arm Debian2Debian Linux Mbed TlsJun 17, 2026 Mar 24, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an input password's length is 0. |
2Arm Fedoraproject2Fedora Mbed TlsJun 17, 2026 Dec 21, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Mbed TLS before 3.1.0, psa_aead_generate_nonce allows policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application. |
3Arm FedoraprojectTrustedfirmware3Fedora Mbed TlsMbed TlsJun 17, 2026 Dec 21, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Mbed TLS before 2.28.0 and 3.x before 3.1.0, psa_cipher_generate_iv and psa_cipher_encrypt allow policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted applic...Show more |
3Arm DebianTrustedfirmware3Debian Linux Mbed TlsMbed TlsJun 17, 2026 Dec 20, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure. |
3Arm DebianSiemens8Debian Linux Logo! Cmr2020 FirmwareLogo! Cmr2040 Firmware+5 moreJun 17, 2026 Aug 23, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certificate is considered va...Show more |
An issue was discovered in Mbed TLS before 2.24.0. The verification of X.509 certificates when matching the expected common name (the cn argument of mbedtls_x509_crt_verify) with the actual certificate name is mishandled...Show more |
2Arm Debian2Debian Linux Mbed TlsJun 17, 2026 Aug 23, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS). There is missing zeroization of plaintext buffers in mbedtls_ssl_read to erase unused application data from memory. |
3Arm DebianSiemens8Debian Linux Logo! Cmr2020 FirmwareLogo! Cmr2040 Firmware+5 moreJun 17, 2026 Aug 23, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). The calculations performed by mbedtls_mpi_exp_mod are not limited; thus, supplying overly large parameters could lead to de...Show more |
2Arm Debian2Debian Linux Mbed TlsJun 17, 2026 Jul 19, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Arm Mbed TLS before 2.24.0. mbedtls_x509_crl_parse_der has a buffer over-read (of one byte). |
2Arm Debian2Debian Linux Mbed TlsJun 17, 2026 Jul 19, 2021 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocation via a CRL. In some situations, an attacker can exploit this by chang...Show more |
2Arm Debian2Debian Linux Mbed TlsJun 17, 2026 Jul 19, 2021 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 An issue was discovered in Arm Mbed TLS before 2.24.0. An attacker can recover a private key (for RSA or static Diffie-Hellman) via a side-channel attack against generation of base blinding/unblinding values. |
2Arm Debian2Debian Linux Mbed TlsJun 17, 2026 Jul 19, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Arm Mbed TLS before 2.23.0. A remote attacker can recover plaintext because a certain Lucky 13 countermeasure doesn't properly consider the case of a hardware accelerator. |
2Arm Debian2Debian Linux Mbed TlsJun 17, 2026 Jul 19, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in Arm Mbed TLS before 2.23.0. A side channel allows recovery of an ECC private key, related to mbedtls_ecp_check_pub_priv, mbedtls_pk_parse_key, mbedtls_pk_parse_keyfile, mbedtls_ecp_mul, and mbe...Show more |
2Arm Debian2Debian Linux Mbed TlsJun 17, 2026 Jul 19, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in Arm Mbed TLS before 2.23.0. Because of a side channel in modular exponentiation, an RSA private key used in a secure enclave could be disclosed. |
3Arm DebianFedoraproject3Debian Linux FedoraMbed TlsJun 17, 2026 Jul 14, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-ch...Show more |
3Arm DebianFedoraproject3Debian Linux FedoraMbed TlsJun 17, 2026 Sep 2, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A Lucky 13 timing side channel in mbedtls_ssl_decrypt_buf in library/ssl_msg.c in Trusted Firmware Mbed TLS through 2.23.0 allows an attacker to recover secret key information. This affects CBC mode because of a computed...Show more |
4Arm DebianFedoraproject+1 more4Debian Linux FedoraMbed Tls+1 moreJun 17, 2026 Apr 15, 2020 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 An issue was discovered in Arm Mbed TLS before 2.16.6 and 2.7.x before 2.7.15. An attacker that can get precise enough side-channel measurements can recover the long-term ECDSA private key by (1) reconstructing the proje...Show more |
3Arm DebianFedoraproject4Debian Linux FedoraMbed Crypto+1 moreJun 17, 2026 Mar 24, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Arm Mbed TLS before 2.16.5 allows attackers to obtain sensitive information (an RSA private key) by measuring cache usage during an import. |
3Arm DebianFedoraproject4Debian Linux FedoraMbed Crypto+1 moreJun 17, 2026 Jan 23, 2020 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to recover the private key v...Show more |
4Arm DebianFedoraproject+1 more5Debian Linux FedoraMbed Crypto+2 moreJun 17, 2026 Sep 26, 2019 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insufficient entropy for blinding, which might allow an attacker to recover a private key via side-channel...Show more |