Description
An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:NExploitability: 3.9 | Impact: 4.2Attack Vector: Network
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: Low
Availability: None
Affected Packages3 packages
Also affects: Fedora 38, 39, 40
🔴Vulnerability Details
3GHSAGHSA-6h48-8w2f-5w94: An issue was discovered in Mbed TLS 2↗2024-03-29 ▶ CVEListCVE-2024-28960: An issue was discovered in Mbed TLS 2↗2024-03-29 ▶ OSVCVE-2024-28960: An issue was discovered in Mbed TLS 2↗2024-03-29 ▶ 📋Vendor Advisories
3Red Hatmbedtls: Insecure handling of shared memory in PSA Crypto APIs↗2024-03-29 ▶ MicrosoftAn issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0 and Mbed Crypto. The PSA Crypto API mishandles shared memory.↗2024-03-12 ▶ DebianCVE-2024-28960: mbedtls - An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x ...↗2024 ▶