First published: Thu May 18 2023(Updated: )
Compiler removal of buffer clearing in sli_crypto_transparent_aead_encrypt_tag in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.
Credit: product-security@silabs.com
Affected Software | Affected Version | How to fix |
---|---|---|
Silabs Gecko Software Development Kit | <=4.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-32096.
The title of this vulnerability is 'Compiler removal of buffer clearing in sli_crypto_transparent_aead_encrypt_tag in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.'
The severity level of CVE-2023-32096 is high, with a CVSS score of 7.5.
This vulnerability affects Silicon Labs Gecko Platform SDK v4.2.1 and earlier, and it results in key material duplication to RAM.
Yes, you can find more information about this vulnerability at the following references: [reference 1](https://community.silabs.com/sfc/servlet.shepherd/document/download/0698Y00000U19lGQAR?operationContext=S1), [reference 2](https://github.com/SiliconLabs/gecko_sdk).