CVE-2023-26084: Low severity arm vulnerability
Published Mar 15, 2023
·Updated
The armv8decaesgcmfull() API of Arm AArch64cryptolib before 86065c6 fails to the verify the authentication tag of AES-GCM protected data, leading to a man-in-the-middle attack. This occurs because of an improperly initialized variable.
Affected Software
1 affected component
Arm AArch64cryptolib<2023-02-20
Remediation
Event History
Mar 15, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-26084.
2
What is the severity of CVE-2023-26084?
The severity of CVE-2023-26084 is low.
3
How does CVE-2023-26084 affect Arm AArch64cryptolib?
CVE-2023-26084 affects Arm AArch64cryptolib before version 86065c6.
4
What is the impact of CVE-2023-26084?
CVE-2023-26084 can result in a man-in-the-middle attack.
5
How can I fix CVE-2023-26084?
To fix CVE-2023-26084, update Arm AArch64cryptolib to version 86065c6 or later.