CVE-2025-47917 affects Mbed TLS before 3.6.4. The vulnerability is caused by inconsistent and misleading API behavior in mbedtls_x509_string_to_names(). The function's head parameter is documented as an output argument, and the documentation does not indicate that the function will free memory referenced by that pointer. In practice, the function calls mbedtls_asn1_free_named_data_list() on the supplied argument, performing a deep free of the existing named-data list. Applications written according to the documented behavior may therefore retain references to memory that has already been freed. Subsequent use of those stale pointers can trigger a use-after-free, and cleanup paths may also lead to double-free conditions. The issue is specifically noted to affect the sample programs x509/cert_write and x509/cert_req, where a use-after-free can occur if the SAN string contains more than one distinguished name.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a working exploit for CVE-2025-47917, a Use-After-Free vulnerability in the mbedtls_x509_string_to_names() function of mbedTLS versions prior to 3.6.4. The exploit is implemented in a single C file (exploit.c) and is designed to be run on Linux with root privileges. It first checks that ASLR is disabled by reading /proc/sys/kernel/randomize_va_space, then exploits the UAF by heap spraying and manipulating freed heap metadata to redirect execution to attacker-supplied shellcode. The shellcode is injected into RWX memory and provides a reverse shell to 192.168.92.187:4454. The README.md provides detailed build and usage instructions, including the need to disable ASLR and prepare a netcat listener. The exploit is operational and provides a root shell if successful. No framework is used; the code is standalone.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.