PT-2021-6568 · Arm+2 · Mbed Tls+2

Kfyatek

·

Published

2020-09-02

·

Updated

2026-02-21

·

CVE-2020-36426

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Arm Mbed TLS versions prior to 2.24.0
Description The issue is related to a buffer over-read in the mbedtls x509 crl parse der function, which can lead to a denial of service. This can be exploited by a remote attacker. The function is part of the Mbed TLS implementation of TLS and SSL protocols.
Recommendations For versions prior to 2.24.0, update to version 2.24.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the mbedtls x509 crl parse der function until a patch is available.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2711
ALT-PU-2021-2234
ALT-PU-2025-10462
BDU:2022-01834
CVE-2020-36426
DLA-3249-1

Affected Products

Alt Linux
Astra Linux
Mbed Tls