CVE-2021-45451: High severity mbed tls vulnerability
Published Dec 21, 2021
·Updated
In Mbed TLS before 3.1.0, psaaeadgeneratenonce allows policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.
Affected Software
3 affected components
Arm mbed TLS<3.1.0
Fedoraproject Fedora=36
Fedoraproject Fedora=37
Remediation
Patch Available
Event History
Dec 21, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-45451?
CVE-2021-45451 is a vulnerability in Mbed TLS before version 3.1.0 that allows policy bypass or oracle-based decryption when the output buffer is accessible to an untrusted application.
2
How does CVE-2021-45451 affect ARM mbed TLS?
CVE-2021-45451 affects ARM mbed TLS versions up to, but excluding, version 3.1.0.
3
How does CVE-2021-45451 affect Fedora?
CVE-2021-45451 affects Fedora versions 36 and 37.
4
What is the severity of CVE-2021-45451?
The severity of CVE-2021-45451 is high with a CVSS score of 7.5.
5
Is there a fix for CVE-2021-45451?
Yes, the fix for CVE-2021-45451 is available in version 3.1.0 of Mbed TLS.