CVE-2023-1132: Key duplication in GSDK
Compiler removal of buffer clearing in
slisedriverkeyagreement
in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-1132?
CVE-2023-1132 is a vulnerability in Silicon Labs Gecko Platform SDK v4.2.1 and earlier where the compiler removes buffer clearing, resulting in key material duplication to RAM.
How severe is CVE-2023-1132?
CVE-2023-1132 has a severity score of 7.5 (High).
What software versions are affected by CVE-2023-1132?
Silicon Labs Gecko Software Development Kit versions up to and including 4.2.1 are affected by CVE-2023-1132.
How can I fix CVE-2023-1132?
To fix CVE-2023-1132, update to a version of Silicon Labs Gecko Software Development Kit that is later than 4.2.1.
Where can I find more information about CVE-2023-1132?
More information about CVE-2023-1132 can be found at the following references: [Silicon Labs Community](https://community.silabs.com/sfc/servlet.shepherd/document/download/0698Y00000U19lGQAR?operationContext=S1), [GitHub](https://github.com/SiliconLabs/gecko_sdk).