Описание
An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.
A flaw was found in Mbed TLS and TF-PSA-Crypto. This vulnerability, a buffer overflow, occurs during the export of public keys for FFDH (Finite Field Diffie-Hellman) keys. A remote attacker could exploit this to potentially execute arbitrary code, gaining full control over the affected system, or cause a denial of service, making the system unavailable.
Отчет
Critical: A buffer overflow flaw in Mbed TLS and TF-PSA-Crypto during FFDH public key export could allow a remote attacker to execute arbitrary code or cause a denial of service. Red Hat products utilizing Mbed TLS for FFDH key operations are susceptible if they expose this functionality to untrusted input.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Дополнительная информация
Статус:
EPSS
9.8 Critical
CVSS3
Связанные уязвимости
An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.
An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.
An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.
An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1. ...
An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.
EPSS
9.8 Critical
CVSS3