CVE-2023-0965: Key duplication in GSDK
Compiler removal of buffer clearing in slicryptoacctransparentkeyagreement in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-0965?
CVE-2023-0965 is a vulnerability in Silicon Labs Gecko Platform SDK that allows for key material duplication to RAM due to the removal of buffer clearing in sli_cryptoacc_transparent_key_agreement.
How severe is CVE-2023-0965?
CVE-2023-0965 has a severity value of 7.5 (high).
What is the affected software?
The affected software is Silicon Labs Gecko Platform SDK up to and including version 4.2.1.
How can I fix CVE-2023-0965?
To fix CVE-2023-0965, it is recommended to update to a version of Silicon Labs Gecko Platform SDK that includes the fix for this vulnerability.
Where can I find more information about CVE-2023-0965?
You can find more information about CVE-2023-0965 on the Silicon Labs Community website and the Silicon Labs GitHub page.