Critical Mbed TLS Vulnerabilities Affect Multiple Ubuntu Releases

Critical Mbed TLS Vulnerabilities Affect Multiple Ubuntu Releases

First seen 26 Mar 2026, 03:17 UTC UbuntuLinuxsecurity 72.0

Article Content

Browse articles
ThreatCluster

Multiple vulnerabilities have been identified in Mbed TLS, impacting Ubuntu 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS. The vulnerabilities include improper handling of memory allocation failures (CVE-2021-44732), crafted inputs leading to denial of service (CVE-2024-23775), and issues with the TLS handshake (CVE-2025-27810). These flaws could allow remote attackers to crash applications or compromise TLS security guarantees. The vulnerabilities were disclosed on March 25, 2026, and patches are available for affected systems. Users are advised to update their systems to mitigate risks associated with these vulnerabilities. The issues were discovered by researchers including Jonathan Winzig, Linh Le, and Ngan Nguyen. The vulnerabilities are critical due to their potential impact on security and service availability.

Key Points: • Mbed TLS vulnerabilities affect Ubuntu 18.04, 20.04, 22.04, and 24.04 LTS. • Critical issues include denial of service and TLS handshake vulnerabilities. • Patches are available; users should update their systems immediately.

Timeline

2021-12-20
CVE-2021-44732 published
2024-01-31
CVE-2024-23775 published
2025-03-25
CVE-2025-27810 published
2025-07-04
CVE-2025-52497 published
2025-07-04
CVE-2025-52496 published
2025-07-20
CVE-2025-48965 published
2025-07-20
CVE-2025-47917 published
2026-03-25
Mbed TLS vulnerabilities disclosed