Bugzilla – Bug 1219337
VUL-0: CVE-2024-23775: mbedtls: buffer overflow in mbedtls_x509_set_extension()
Last modified: 2024-01-30 11:45:21 UTC
CVE-2024-23775 Buffer overflow in mbedtls_x509_set_extension(). When writing x509 extensions we failed to validate inputs passed in to mbedtls_x509_set_extension(), which could result in an integer overflow, causing a zero-length buffer to be allocated to hold the extension. The extension would then be copied into the buffer, causing a heap buffer overflow. https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2024-01-2/ Resolution: update net-libs/mbedtls to 2.28.7 and 3.5.2. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-23775 https://bugzilla.redhat.com/show_bug.cgi?id=2261598
Tracking as affected: - openSUSE:Backports:SLE-15-SP4/mbedtls 2.28.0 - openSUSE:Backports:SLE-15-SP5/mbedtls 2.28.2 - openSUSE:Factory/mbedtls 3.5.1 - openSUSE:Factory/mbedtls-2 2.28.6