First published: Tue Dec 21 2021(Updated: )
In Mbed TLS before 3.1.0, psa_aead_generate_nonce allows policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ARM mbed TLS | <3.1.0 | |
Fedoraproject Fedora | =36 | |
Fedoraproject Fedora | =37 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-45451 is a vulnerability in Mbed TLS before version 3.1.0 that allows policy bypass or oracle-based decryption when the output buffer is accessible to an untrusted application.
CVE-2021-45451 affects ARM mbed TLS versions up to, but excluding, version 3.1.0.
CVE-2021-45451 affects Fedora versions 36 and 37.
The severity of CVE-2021-45451 is high with a CVSS score of 7.5.
Yes, the fix for CVE-2021-45451 is available in version 3.1.0 of Mbed TLS.