PT-2025-30212 · Mbed Tls+3 · Mbed Tls+3

Published

2025-01-01

·

Updated

2026-05-05

·

CVE-2025-47917

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions mbedtls versions prior to 3.6.4
Description The software contains a use-after-free issue in the mbedtls x509 string to names() function. This function incorrectly frees a pointer that application code may still be using, leading to a potential use-after-free or double-free condition. The sample programs cert write and cert req are affected when the Subject Alternative Name (SAN) string contains more than one Distinguished Name (DN).
Recommendations Update to mbedtls version 3.6.4 or later.

Exploit

Fix

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2025-09513
CVE-2025-47917
DLA-4274-1
DLA-4274-2
USN-8123-1

Affected Products

Debian
Linuxmint
Ubuntu
Mbed Tls