CVE-2018-0498: Medium severity Arm mbed TLS vulnerability
Published Jul 28, 2018
·Updated
ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows local users to achieve partial plaintext recovery (for a CBC based ciphersuite) via a cache-based side-channel attack.
Affected Software
6 affected componentsFixes available
Arm mbed TLS<2.1.14
Arm mbed TLS>=2.2.0<2.7.5
Arm mbed TLS>=2.8.0<2.12.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
debian/mbedtls
2.16.9-0.12.16.9-0.1+deb11u32.28.3-13.6.5-0.1~deb13u13.6.5-0.1
Event History
Jul 28, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Data Sourced
via NVD·05:29 PM
DescriptionSeverityAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:43 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·10:14 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·10:15 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2018-0498.
2
What is the severity of CVE-2018-0498?
The severity of CVE-2018-0498 is medium.
3
How does CVE-2018-0498 affect ARM mbed TLS?
CVE-2018-0498 allows local users to achieve partial plaintext recovery (for a CBC based ciphersuite) via a cache-based side-channel attack in ARM mbed TLS before version 2.12.0, 2.7.5, and 2.1.14.
4
How can I fix CVE-2018-0498 on Ubuntu?
To fix CVE-2018-0498 on Ubuntu, update the mbedtls package to version 2.12.0-1 or higher.
5
Where can I find more information about CVE-2018-0498?
You can find more information about CVE-2018-0498 at the following link: [CVE-2018-0498](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0498).