An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory.
2024-03-29T06:15:07.270
2025-11-04T22:15:59.973
Modified
CVSSv3.1: 8.2 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | arm | mbed_crypto | ≤ 3.1.0 | Yes |
| Application | arm | mbed_tls | < 2.28.8 | Yes |
| Application | arm | mbed_tls | < 3.6.0 | Yes |
| Operating System | fedoraproject | fedora | 38 | Yes |
| Operating System | fedoraproject | fedora | 39 | Yes |
| Operating System | fedoraproject | fedora | 40 | Yes |