Bugzilla – Bug 1222157
VUL-0: CVE-2024-28960: mbedtls,mbedtls-2: Insecure handling of shared memory in PSA Crypto APIs
Last modified: 2024-03-29 10:15:03 UTC
An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-28960 https://mbed-tls.readthedocs.io/en/latest/tech-updates/security-advisories/ https://github.com/Mbed-TLS/mbedtls-docs/blob/main/security-advisories/mbedtls-security-advisory-2024-03.md https://www.cve.org/CVERecord?id=CVE-2024-28960 https://bugzilla.redhat.com/show_bug.cgi?id=2272172
Tracking as affected: - openSUSE:Backports:SLE-15-SP5/mbedtls 2.28.2 - openSUSE:Backports:SLE-15-SP6/mbedtls 3.5.1 - openSUSE:Backports:SLE-15-SP6/mbedtls-2 2.28.6 - openSUSE:Factory/mbedtls 3.5.2 - openSUSE:Factory/mbedtls-2 2.28.7