← Back

CVE-2024-28960

nvd nist
Published: Mar 29, 2024Modified: Nov 4, 2025

JSON object

Loading...
8.2
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Exploitability: 3.9 / Impact: 4.2
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory.

Affected (6)

2 products
Mbed Crypto
Mbed Tls
1 product
Fedora
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Up to 3.1.0
Arm
From 2.1.8 to 2.28.8
From 3.0.0 to 3.6.0
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 38
Version 39
Version 40

References (13)

Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.