CVE-2018-0487: Arm Mbed TLS
Critical severity, CVSS 9.8. EPSS: 3.3% chance of exploitation in the next 30 days.
ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via a crafted certificate chain that is mishandled during RSASSA-PSS signature verification within a TLS or DTLS session.
Affected products
- Arm Mbed TLS: from 1.3.8, before 1.3.22 (fixed in 1.3.22); from 2.1.0, before 2.1.10 (fixed in 2.1.10); from 2.2.0, before 2.7.0 (fixed in 2.7.0)
- Debian Debian Linux: version 8.0 only; version 9.0 only
Published 2018-02-13. Last modified 2026-06-17.