First published: Thu May 18 2023(Updated: )
Compiler removal of buffer clearing in sli_se_driver_key_agreement in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.
Credit: product-security@silabs.com
Affected Software | Affected Version | How to fix |
---|---|---|
Silabs Gecko Software Development Kit | <=4.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1132 is a vulnerability in Silicon Labs Gecko Platform SDK v4.2.1 and earlier where the compiler removes buffer clearing, resulting in key material duplication to RAM.
CVE-2023-1132 has a severity score of 7.5 (High).
Silicon Labs Gecko Software Development Kit versions up to and including 4.2.1 are affected by CVE-2023-1132.
To fix CVE-2023-1132, update to a version of Silicon Labs Gecko Software Development Kit that is later than 4.2.1.
More information about CVE-2023-1132 can be found at the following references: [Silicon Labs Community](https://community.silabs.com/sfc/servlet.shepherd/document/download/0698Y00000U19lGQAR?operationContext=S1), [GitHub](https://github.com/SiliconLabs/gecko_sdk).