Debian Package Tracker
Register | Log in
Subscribe

mbedtls

Choose email to subscribe with

general
  • source: mbedtls (main)
  • version: 3.6.7-3
  • maintainer: Debian IoT Maintainers (archive) (DMD)
  • uploaders: Andrea Pappacoda [DMD]
  • arch: all any
  • std-ver: 4.7.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 2.16.9-0.1
  • o-o-sec: 2.16.9-0.1+deb11u4
  • oldstable: 2.28.3-1
  • stable: 3.6.5-0.1~deb13u1
  • testing: 3.6.7-3
  • unstable: 3.6.7-3
versioned links
  • 2.16.9-0.1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.16.9-0.1+deb11u4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.28.3-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.6.5-0.1~deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.6.7-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libmbedcrypto16
  • libmbedtls-dev (1 bugs: 0, 1, 0, 0)
  • libmbedtls-doc
  • libmbedtls21
  • libmbedx509-7
action needed
29 security issues in bullseye high

There are 29 open security issues in bullseye.

22 important issues:
  • CVE-2025-54764: Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_inv or mbedtls_mpi_gcd.
  • CVE-2026-25832:
  • CVE-2026-25835: Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG).
  • CVE-2026-34872: An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other party can force the shared secret into a small set of values (lack of contributory behavior). This is a problem for protocols that depend on contributory behavior (which is not the case for TLS). The attack can be carried by the peer, or depending on the protocol by an active network attacker (person in the middle).
  • CVE-2026-34873: An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.
  • CVE-2026-34874: An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0.
  • CVE-2026-34875: An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.
  • CVE-2026-35336:
  • CVE-2026-49300:
  • CVE-2026-50579:
  • CVE-2026-50580:
  • CVE-2026-50581:
  • CVE-2026-50583:
  • CVE-2026-50584:
  • CVE-2026-50585:
  • CVE-2026-50586:
  • CVE-2026-50587:
  • CVE-2026-50588:
  • CVE-2026-50640:
  • CVE-2026-50713:
  • CVE-2026-54435:
  • CVE-2026-54441:
4 issues postponed or untriaged:
  • CVE-2024-23170: (needs triaging) An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations. This side channel could be sufficient for a local attacker to recover the plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.
  • CVE-2024-23775: (needs triaging) Integer Overflow vulnerability in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2, allows attackers to cause a denial of service (DoS) via mbedtls_x509_set_extension().
  • CVE-2024-28755: (needs triaging) An issue was discovered in Mbed TLS 3.5.x before 3.6.0. When an SSL context was reset with the mbedtls_ssl_session_reset() API, the maximum TLS version to be negotiated was not restored to the configured one. An attacker was able to prevent an Mbed TLS server from establishing any TLS 1.3 connection, potentially resulting in a Denial of Service or forced version downgrade from TLS 1.3 to TLS 1.2.
  • CVE-2024-28960: (needs triaging) An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory.
3 ignored issues:
  • CVE-2022-35409: An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0. In some configurations, an unauthenticated attacker can send an invalid ClientHello message to a DTLS server that causes a heap-based buffer over-read of up to 255 bytes. This can cause a server crash or possibly information disclosure based on error responses. Affected configurations have MBEDTLS_SSL_DTLS_CLIENT_PORT_REUSE enabled and MBEDTLS_SSL_IN_CONTENT_LEN less than a threshold that depends on the configuration: 258 bytes if using mbedtls_ssl_cookie_check, and possibly up to 571 bytes with a custom cookie check function.
  • CVE-2025-27809: Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.
  • CVE-2025-27810: Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.
Created: 2025-10-21 Last update: 2026-07-27 00:30
lintian reports 2 errors and 1 warning high
Lintian reports 2 errors and 1 warning about this package. You should make the package lintian clean getting rid of them.
Created: 2026-05-16 Last update: 2026-07-23 06:00
1 new commit since last upload, is it time to release? normal
vcswatch reports that this package seems to have new commits in its VCS but has not yet updated debian/changelog. You should consider updating the Debian changelog and uploading this new version into the archive.

Here are the relevant commit logs:
commit d7302e234cef3b12aeb5684189617e5b462ea9fe
Author: Bastian Germann <bage@debian.org>
Date:   Wed Jul 22 23:47:45 2026 +0200

    Adjust long description for current features (Closes: #1126421)


https://salsa.debian.org/api/v4/projects/debian-iot-team%2Fmbedtls API request failed: 401 Unauthorized at /srv/qa.debian.org/data/vcswatch/vcswatch line 410.
Created: 2026-07-22 Last update: 2026-07-29 02:33
16 low-priority security issues in trixie low

There are 16 open security issues in trixie.

16 issues left for the package maintainer to handle:
  • CVE-2026-25832: (needs triaging)
  • CVE-2026-35336: (needs triaging)
  • CVE-2026-49300: (needs triaging)
  • CVE-2026-50579: (needs triaging)
  • CVE-2026-50580: (needs triaging)
  • CVE-2026-50581: (needs triaging)
  • CVE-2026-50583: (needs triaging)
  • CVE-2026-50584: (needs triaging)
  • CVE-2026-50585: (needs triaging)
  • CVE-2026-50586: (needs triaging)
  • CVE-2026-50587: (needs triaging)
  • CVE-2026-50588: (needs triaging)
  • CVE-2026-50640: (needs triaging)
  • CVE-2026-50713: (needs triaging)
  • CVE-2026-54435: (needs triaging)
  • CVE-2026-54441: (needs triaging)

You can find information about how to handle these issues in the security team's documentation.

7 issues that should be fixed with the next stable update:
  • CVE-2026-25834: Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.
  • CVE-2026-25835: Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG).
  • CVE-2026-34872: An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other party can force the shared secret into a small set of values (lack of contributory behavior). This is a problem for protocols that depend on contributory behavior (which is not the case for TLS). The attack can be carried by the peer, or depending on the protocol by an active network attacker (person in the middle).
  • CVE-2026-34873: An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.
  • CVE-2026-34874: An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0.
  • CVE-2026-34875: An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.
  • CVE-2026-34876: An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation of the multipart CCM API with an oversized tag_len parameter. This is caused by missing validation of the tag_len parameter against the size of the internal 16-byte authentication buffer. The issue affects the public multipart CCM API in Mbed TLS 3.x, where mbedtls_ccm_finish() can be invoked directly by applications. In Mbed TLS 4.x versions prior to the fix, the same missing validation exists in the internal implementation; however, the function is not exposed as part of the public API. Exploitation requires application-level invocation of the multipart CCM API.
Created: 2026-07-22 Last update: 2026-07-27 00:30
12 low-priority security issues in bookworm low

There are 12 open security issues in bookworm.

12 issues left for the package maintainer to handle:
  • CVE-2024-23170: (needs triaging) An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations. This side channel could be sufficient for a local attacker to recover the plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.
  • CVE-2024-23775: (needs triaging) Integer Overflow vulnerability in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2, allows attackers to cause a denial of service (DoS) via mbedtls_x509_set_extension().
  • CVE-2024-28755: (needs triaging) An issue was discovered in Mbed TLS 3.5.x before 3.6.0. When an SSL context was reset with the mbedtls_ssl_session_reset() API, the maximum TLS version to be negotiated was not restored to the configured one. An attacker was able to prevent an Mbed TLS server from establishing any TLS 1.3 connection, potentially resulting in a Denial of Service or forced version downgrade from TLS 1.3 to TLS 1.2.
  • CVE-2024-28960: (needs triaging) An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory.
  • CVE-2025-27809: (needs triaging) Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.
  • CVE-2025-27810: (needs triaging) Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.
  • CVE-2026-25835: (needs triaging) Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG).
  • CVE-2026-34872: (needs triaging) An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other party can force the shared secret into a small set of values (lack of contributory behavior). This is a problem for protocols that depend on contributory behavior (which is not the case for TLS). The attack can be carried by the peer, or depending on the protocol by an active network attacker (person in the middle).
  • CVE-2026-34873: (needs triaging) An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.
  • CVE-2026-34874: (needs triaging) An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0.
  • CVE-2026-34875: (needs triaging) An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.
  • CVE-2026-34876: (needs triaging) An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation of the multipart CCM API with an oversized tag_len parameter. This is caused by missing validation of the tag_len parameter against the size of the internal 16-byte authentication buffer. The issue affects the public multipart CCM API in Mbed TLS 3.x, where mbedtls_ccm_finish() can be invoked directly by applications. In Mbed TLS 4.x versions prior to the fix, the same missing validation exists in the internal implementation; however, the function is not exposed as part of the public API. Exploitation requires application-level invocation of the multipart CCM API.

You can find information about how to handle these issues in the security team's documentation.

Created: 2024-01-22 Last update: 2026-07-27 00:30
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.7.2).
Created: 2025-12-23 Last update: 2026-07-22 12:02
news
[rss feed]
  • [2026-07-24] mbedtls 3.6.7-3 MIGRATED to testing (Debian testing watch)
  • [2026-07-22] Accepted mbedtls 3.6.7-3 (source) into unstable (Bastian Germann) (signed by: bage@debian.org)
  • [2026-07-21] Accepted mbedtls 3.6.7-2 (source) into unstable (Andrea Pappacoda)
  • [2026-05-21] mbedtls 3.6.6-0.1 MIGRATED to testing (Debian testing watch)
  • [2026-05-15] Accepted mbedtls 3.6.6-0.1 (source) into unstable (Adrian Bunk)
  • [2026-04-27] Accepted mbedtls 2.16.9-0.1+deb11u4 (source) into oldoldstable-security (Andrej Shadura) (signed by: Andrew Shadura)
  • [2026-01-03] Accepted mbedtls 3.6.5-0.1~deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Adrian Bunk)
  • [2025-11-23] mbedtls 3.6.5-0.1 MIGRATED to testing (Debian testing watch)
  • [2025-11-21] Accepted mbedtls 3.6.5-0.1 (source) into unstable (Adrian Bunk)
  • [2025-08-26] Accepted mbedtls 2.16.9-0.1+deb11u3 (source) into oldoldstable-security (Andrej Shadura) (signed by: Andrew Shadura)
  • [2025-08-10] Accepted mbedtls 2.16.9-0.1+deb11u2 (source) into oldoldstable-security (Andrej Shadura) (signed by: Andrew Shadura)
  • [2025-07-23] mbedtls 3.6.4-2 MIGRATED to testing (Debian testing watch)
  • [2025-07-14] Accepted mbedtls 3.6.4-2 (source) into unstable (Andrea Pappacoda)
  • [2025-07-13] Accepted mbedtls 3.6.4-1 (source) into unstable (Andrea Pappacoda)
  • [2025-06-30] Accepted mbedtls 2.16.9-0.1+deb11u1 (source) into oldstable-security (Andrej Shadura) (signed by: Andrew Shadura)
  • [2025-04-08] mbedtls 3.6.3-1 MIGRATED to testing (Debian testing watch)
  • [2025-04-05] Accepted mbedtls 3.6.3-1 (source) into unstable (Andrea Pappacoda)
  • [2024-11-23] mbedtls 3.6.2-3 MIGRATED to testing (Debian testing watch)
  • [2024-11-17] Accepted mbedtls 3.6.2-3 (source) into unstable (Andrea Pappacoda)
  • [2024-11-06] Accepted mbedtls 3.6.2-2 (source) into unstable (Andrea Pappacoda)
  • [2024-10-23] Accepted mbedtls 3.6.2-1 (source) into unstable (Andrea Pappacoda)
  • [2024-10-17] Accepted mbedtls 3.6.0-3 (source) into unstable (Andrea Pappacoda)
  • [2024-04-25] mbedtls 2.28.8-1 MIGRATED to testing (Debian testing watch)
  • [2024-04-10] Accepted mbedtls 3.6.0-2 (source) into experimental (Andrea Pappacoda)
  • [2024-04-08] Accepted mbedtls 3.6.0-1 (source amd64 all) into experimental (Debian FTP Masters) (signed by: bage@debian.org)
  • [2024-03-31] Accepted mbedtls 2.28.8-1 (source) into unstable (Andrea Pappacoda)
  • [2024-02-29] Accepted mbedtls 2.28.7-1.1 (source) into unstable (Graham Inggs)
  • [2024-02-03] Accepted mbedtls 2.28.7-1.1~exp1 (source) into experimental (Graham Inggs)
  • [2024-01-31] mbedtls 2.28.7-1 MIGRATED to testing (Debian testing watch)
  • [2024-01-31] mbedtls 2.28.7-1 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 3
  • RC: 0
  • I&N: 1
  • M&W: 1
  • F&P: 1
  • patch: 0
links
  • homepage
  • lintian (2, 1)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 3.6.6-0.1ubuntu1
  • patches for 3.6.6-0.1ubuntu1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing