Arm
arm
193 CVEs • 141 products
Products (141)
Click to collapseToggle
Products (141)
Click to collapse
CVEs (193)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Arm Trustedfirmware2Mbed Tls Mbed TlsJul 24, 2026 Apr 2, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who can modify the serialized structures to...Show more |
An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation of the multipart CCM...Show more |
2Arm Trustedfirmware2Mbed Tls Mbed TlsJun 17, 2026 Apr 1, 2026 N/A· v4 9.1 CRITICAL· v3 N/A· v2 An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session. |
An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other par...Show more |
In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected. |
An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0. |
2Arm Trustedfirmware3Mbed Tls Tf Psa CryptoTf Psa CryptoJun 17, 2026 Apr 1, 2026 N/A· v4 6.7 MEDIUM· v3 N/A· v2 An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG). |
3Arm LinaroTrustedfirmware5Mbed Tls Mbed TlsTf Psa Crypto+2 moreJun 17, 2026 Apr 1, 2026 N/A· v4 7.7 HIGH· v3 N/A· v2 Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG). |
Mbed TLS 3.5.0 to 3.6.5 fixed in 3.6.6 and 4.1.0 has a buffer overflow in the x509_inet_pton_ipv6() function |
2Arm Trustedfirmware4Mbed Tls Mbed TlsTf Psa Crypto+1 moreJun 17, 2026 Apr 1, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys. |
2Arm Trustedfirmware2Mbed Tls Mbed TlsJun 17, 2026 Apr 1, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade. |
An issue has been identified in Arm C1-Pro before r1p2-50eac0, where, under certain conditions, a TLBI+DSB might fail to ensure the completion of memory accesses related to SME. |
1Arm 11C1 Premium Firmware C1 Ultra FirmwareCortex A710 Firmware+8 moreJun 17, 2026 Jan 14, 2026 N/A· v4 7.9 HIGH· v3 N/A· v2 In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a TLBI is issued to the PE, either by the same PE or another PE in the shareability domain. In this ca...Show more |
1Arm 25th Gen Gpu Architecture Kernel Driver Valhall Gpu Kernel DriverJun 17, 2026 Dec 1, 2025 N/A· v4 4.0 MEDIUM· v3 N/A· v2 Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU processing operations to gain acces...Show more |
1Arm 25th Gen Gpu Architecture Kernel Driver Valhall Gpu Kernel DriverJun 17, 2026 Dec 1, 2025 N/A· v4 5.1 MEDIUM· v3 N/A· v2 Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations to gai...Show more |
1Arm 25th Gen Gpu Architecture Kernel Driver Valhall Gpu Kernel DriverJun 17, 2026 Dec 1, 2025 N/A· v4 5.1 MEDIUM· v3 N/A· v2 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform impr...Show more |
Mbed TLS through 3.6.4 has an Observable Timing Discrepancy. |
Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_inv or mbedtls_mpi_gcd. |
1Arm 35th Gen Gpu Architecture Kernel Driver Bifrost Gpu Kernel DriverValhall Gpu Kernel DriverJun 17, 2026 Sep 8, 2025 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU mem...Show more |
1Arm 35th Gen Gpu Architecture Userspace Driver Bifrost Gpu Userspace DriverValhall Gpu Userspace DriverJun 17, 2026 Aug 4, 2025 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Use After Free vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU...Show more |