An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory.
2024-03-29T06:15:07.270
2025-05-28T17:42:17.887
Analyzed
CVSSv3.1: 8.2 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | arm | mbed_crypto | ≤ 3.1.0 | Yes |
Application | arm | mbed_tls | < 2.28.8 | Yes |
Application | arm | mbed_tls | < 3.6.0 | Yes |
Operating System | fedoraproject | fedora | 38 | Yes |
Operating System | fedoraproject | fedora | 39 | Yes |
Operating System | fedoraproject | fedora | 40 | Yes |