CVE-2021-45450
21.12.2021, 07:15
In Mbed TLS before 2.28.0 and 3.x before 3.1.0, psa_cipher_generate_iv and psa_cipher_encrypt allow policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.Enginsight
Vendor | Product | Version |
---|---|---|
arm | mbed_tls | 2.22.0 ≤ 𝑥 < 2.28.0 |
arm | mbed_tls | 3.0.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References