First published: Thu May 18 2023(Updated: )
Compiler removal of buffer clearing in sli_se_opaque_import_key in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.
Credit: product-security@silabs.com
Affected Software | Affected Version | How to fix |
---|---|---|
Silabs Gecko Software Development Kit | <=4.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-2481.
The severity of CVE-2023-2481 is high.
The vulnerability occurs due to the compiler removing buffer clearing in sli_se_opaque_import_key function in Silicon Labs Gecko Platform SDK v4.2.1 and earlier.
The impact of the vulnerability is key material duplication to RAM.
To fix this vulnerability, update to a version of Silicon Labs Gecko Platform SDK that is later than v4.2.1.