Known vulnerabilities in mbedtls (Ubuntu package)

Software CPE: cpe:2.3:o:canonical:mbedtls_ubuntu_package:*:*:*:*:*:ubuntu:*:*
Total vulnerabilities: 12
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting mbedtls (Ubuntu package) mbedtls (Ubuntu package) is affected by 12 known vulnerabilities: 4 high, 5 medium, 3 low Critical High Medium Low

Vulnerabilities (12)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU112445 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-52496
CWE-362 Medium
No
No
2.8.0-1ubuntu0.1~esm1, 2.16.4-1ubuntu2+esm1, 2.28.0-1ubuntu0.1~esm1, 2.28.8-1ubuntu0.1~esm1 07.07.2025 SB2025070782
SB2025070784
SB2025070785
and 3 more
#VU112444 - Out-of-bounds read
CVE-2025-52497
CWE-125 Medium
No
No
2.8.0-1ubuntu0.1~esm1, 2.16.4-1ubuntu2+esm1, 2.28.0-1ubuntu0.1~esm1, 2.28.8-1ubuntu0.1~esm1 07.07.2025 SB2025070782
SB2025070784
SB2025070785
and 3 more
#VU112442 - NULL Pointer Dereference
CVE-2025-48965
CWE-476 Medium
No
No
2.8.0-1ubuntu0.1~esm1, 2.16.4-1ubuntu2+esm1, 2.28.0-1ubuntu0.1~esm1, 2.28.8-1ubuntu0.1~esm1 07.07.2025 SB2025070782
SB2025110101
SB2026033149
#VU112441 - Use After Free
CVE-2025-47917
CWE-416 High
No
No
2.8.0-1ubuntu0.1~esm1, 2.16.4-1ubuntu2+esm1, 2.28.0-1ubuntu0.1~esm1, 2.28.8-1ubuntu0.1~esm1 07.07.2025 SB2025070782
SB2025110101
SB2026033149
#VU106011 - Improper Authentication
CVE-2025-27810
CWE-287 Medium
No
No
2.8.0-1ubuntu0.1~esm1, 2.16.4-1ubuntu2+esm1, 2.28.0-1ubuntu0.1~esm1, 2.28.8-1ubuntu0.1~esm1 25.03.2025 SB2025032526
SB2026033149
#VU86232 - Integer overflow
CVE-2024-23775
CWE-190 Medium
No
No
2.8.0-1ubuntu0.1~esm1, 2.16.4-1ubuntu2+esm1, 2.28.0-1ubuntu0.1~esm1, 2.28.8-1ubuntu0.1~esm1 07.02.2024 SB2024020751
SB2024020761
SB2024020762
and 4 more
#VU59050 - Double Free
CVE-2021-44732
CWE-415 High
No
No
2.8.0-1ubuntu0.1~esm1, 2.16.4-1ubuntu2+esm1, 2.28.0-1ubuntu0.1~esm1, 2.28.8-1ubuntu0.1~esm1 17.12.2021 SB2021121719
SB2026033149
#VU14174 - Exposure of sensitive information to an unauthorized actor
CVE-2018-0497
CWE-200 Low
No
No
2.2.1-2ubuntu0.3 02.08.2018 SB2018080208
SB2018091801
SB2020020801
and 4 more
#VU14173 - Exposure of sensitive information to an unauthorized actor
CVE-2018-0498
CWE-200 Low
No
No
2.2.1-2ubuntu0.3 02.08.2018 SB2018080208
SB2018091801
SB2020020801
and 1 more
#VU11120 - Integer overflow
CVE-2017-18187
CWE-190 Low
No
No
2.2.1-2ubuntu0.3 15.03.2018 SB2018031515
SB2018032104
SB2018042302
and 6 more
#VU10955 - Buffer overflow
CVE-2018-0487
CWE-120 High
No
No
2.2.1-2ubuntu0.3 13.03.2018 SB2018020130
SB2018031515
SB2018032104
and 7 more
#VU10943 - Improper input validation
CVE-2018-0488
CWE-20 High
No
No
2.2.1-2ubuntu0.3 13.03.2018 SB2018020511
SB2018031515
SB2018032104
and 7 more