PT-2024-1659 · Mbed Tls+6 · Mbed Tls+6

Jonathan Winzig

·

Published

2024-01-09

·

Updated

2026-05-05

·

CVE-2024-23775

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Mbed TLS versions 2.x through 2.28.6 Mbed TLS versions 3.x through 3.5.1
Description The issue is related to an integer overflow vulnerability in the mbedtls x509 set extension() function, which can be exploited by attackers to cause a denial of service (DoS). This vulnerability allows a remote attacker to trigger the DoS.
Recommendations For Mbed TLS versions 2.x through 2.28.6, update to version 2.28.7 or later. For Mbed TLS versions 3.x through 3.5.1, update to version 3.5.2 or later. As a temporary workaround, consider restricting the use of the mbedtls x509 set extension() function until a patch is available.

Fix

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-15509
ALT-PU-2025-10462
AZL-47655
BDU:2024-01341
CVE-2024-23775
USN-8123-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Mbed Tls
Red Os
Ubuntu