PT-2025-30212 · Mbed Tls+3 · Mbed Tls+3
Published
2025-01-01
·
Updated
2026-05-05
·
CVE-2025-47917
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
mbedtls versions prior to 3.6.4
Description
The software contains a use-after-free issue in the
mbedtls x509 string to names() function. This function incorrectly frees a pointer that application code may still be using, leading to a potential use-after-free or double-free condition. The sample programs cert write and cert req are affected when the Subject Alternative Name (SAN) string contains more than one Distinguished Name (DN).Recommendations
Update to mbedtls version 3.6.4 or later.
Exploit
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Linuxmint
Ubuntu
Mbed Tls