Known vulnerabilities in mbedtls (Ubuntu package)
Vendor:
Canonical Ltd.
Software:
mbedtls (Ubuntu package)
Software CPE:
cpe:2.3:o:canonical:mbedtls_ubuntu_package:*:*:*:*:*:ubuntu:*:*
Website:
https://www.ubuntu.com/
Total vulnerabilities:
12
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
2.8.0-1ubuntu0.1~esm1
2.16.4-1ubuntu2+esm1
2.28.0-1ubuntu0.1~esm1
2.28.8-1ubuntu0.1~esm1
3.6.2-3ubuntu1
3.6.2-3
3.6.2-2ubuntu1
3.6.2-2
3.6.2-1ubuntu4
3.6.2-1ubuntu3
3.6.2-1ubuntu2
3.6.2-1ubuntu1
3.6.0-1
3.6.0-2
3.6.0-3
3.6.2-1
2.28.8-1
2.28.7-1.1ubuntu2
2.28.7-1
2.28.7-1ubuntu1
2.28.7-1.1
2.28.7-1.1ubuntu1
2.28.6-1ubuntu1
2.28.6-1
2.28.4-1
2.28.5-1
2.28.3-1
2.28.2-1
2.28.1-1
2.28.0-0.3
2.28.0-2
2.28.0-1build1
2.28.0-0.1
2.28.0-0.2
2.28.0-1
2.16.11-0.3
2.16.11-0.2
2.16.11-0.1
2.16.11-0.1ubuntu1
2.16.9-0.1
2.16.9-0.1ubuntu1
2.16.5-1
2.16.4-1ubuntu1
2.16.5
2.16.5-1ubuntu1
2.16.4
2.16.4-1ubuntu2
2.16.2
2.8.0
2.2.1
2.16.4-1build1
2.16.4-1
2.16.3-1
2.16.2-1
2.16.0-1
2.14.1-2
2.14.1-1
2.13.0-1
2.13.0-2
2.13.0-3
2.12.0-1
2.11.0-1
2.9.0-1
2.9.0-2
2.8.0-1
2.7.0-1
2.7.0-2
2.6.0-1
2.5.1-1ubuntu1
2.4.2-1ubuntu0.1
2.2.1-2ubuntu0.3
2.2.1-2ubuntu0.2
2.5.1-1
2.4.2-1
2.4.0-1
2.3.0-1ubuntu0.1
2.3.0-1
2.2.1-3
2.2.1-2ubuntu0.1
2.2.1-2
2.2.1-1
2.2.0-1
2.1.2-1
Vulnerabilities (12)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU112445 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2025-52496 |
CWE-362 | Medium | 2.8.0-1ubuntu0.1~esm1, 2.16.4-1ubuntu2+esm1, 2.28.0-1ubuntu0.1~esm1, 2.28.8-1ubuntu0.1~esm1 | 07.07.2025 |
SB2025070782 SB2025070784 SB2025070785 and 3 more |
||
| #VU112444 - Out-of-bounds read CVE-2025-52497 |
CWE-125 | Medium | 2.8.0-1ubuntu0.1~esm1, 2.16.4-1ubuntu2+esm1, 2.28.0-1ubuntu0.1~esm1, 2.28.8-1ubuntu0.1~esm1 | 07.07.2025 |
SB2025070782 SB2025070784 SB2025070785 and 3 more |
||
| #VU112442 - NULL Pointer Dereference CVE-2025-48965 |
CWE-476 | Medium | 2.8.0-1ubuntu0.1~esm1, 2.16.4-1ubuntu2+esm1, 2.28.0-1ubuntu0.1~esm1, 2.28.8-1ubuntu0.1~esm1 | 07.07.2025 |
SB2025070782 SB2025110101 SB2026033149 |
||
| #VU112441 - Use After Free CVE-2025-47917 |
CWE-416 | High | 2.8.0-1ubuntu0.1~esm1, 2.16.4-1ubuntu2+esm1, 2.28.0-1ubuntu0.1~esm1, 2.28.8-1ubuntu0.1~esm1 | 07.07.2025 |
SB2025070782 SB2025110101 SB2026033149 |
||
| #VU106011 - Improper Authentication CVE-2025-27810 |
CWE-287 | Medium | 2.8.0-1ubuntu0.1~esm1, 2.16.4-1ubuntu2+esm1, 2.28.0-1ubuntu0.1~esm1, 2.28.8-1ubuntu0.1~esm1 | 25.03.2025 |
SB2025032526 SB2026033149 |
||
| #VU86232 - Integer overflow CVE-2024-23775 |
CWE-190 | Medium | 2.8.0-1ubuntu0.1~esm1, 2.16.4-1ubuntu2+esm1, 2.28.0-1ubuntu0.1~esm1, 2.28.8-1ubuntu0.1~esm1 | 07.02.2024 |
SB2024020751 SB2024020761 SB2024020762 and 4 more |
||
| #VU59050 - Double Free CVE-2021-44732 |
CWE-415 | High | 2.8.0-1ubuntu0.1~esm1, 2.16.4-1ubuntu2+esm1, 2.28.0-1ubuntu0.1~esm1, 2.28.8-1ubuntu0.1~esm1 | 17.12.2021 |
SB2021121719 SB2026033149 |
||
| #VU14174 - Exposure of sensitive information to an unauthorized actor CVE-2018-0497 |
CWE-200 | Low | 2.2.1-2ubuntu0.3 | 02.08.2018 |
SB2018080208 SB2018091801 SB2020020801 and 4 more |
||
| #VU14173 - Exposure of sensitive information to an unauthorized actor CVE-2018-0498 |
CWE-200 | Low | 2.2.1-2ubuntu0.3 | 02.08.2018 |
SB2018080208 SB2018091801 SB2020020801 and 1 more |
||
| #VU11120 - Integer overflow CVE-2017-18187 |
CWE-190 | Low | 2.2.1-2ubuntu0.3 | 15.03.2018 |
SB2018031515 SB2018032104 SB2018042302 and 6 more |
||
| #VU10955 - Buffer overflow CVE-2018-0487 |
CWE-120 | High | 2.2.1-2ubuntu0.3 | 13.03.2018 |
SB2018020130 SB2018031515 SB2018032104 and 7 more |
||
| #VU10943 - Improper input validation CVE-2018-0488 |
CWE-20 | High | 2.2.1-2ubuntu0.3 | 13.03.2018 |
SB2018020511 SB2018031515 SB2018032104 and 7 more |