First published: Thu May 18 2023(Updated: )
Compiler removal of buffer clearing in sli_crypto_transparent_aead_decrypt_tag in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.
Credit: product-security@silabs.com
Affected Software | Affected Version | How to fix |
---|---|---|
Silabs Gecko Software Development Kit | <=4.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-32097.
CVE-2023-32097 has a severity rating of 7.5 (high).
The vulnerability in sli_crypto_transparent_aead_decrypt_tag occurs due to the compiler's removal of buffer clearing.
Silicon Labs Gecko Platform SDK v4.2.1 and earlier versions are affected by CVE-2023-32097.
CVE-2023-32097 is associated with CWE-14 (Compiler Removal of Code to Clear Buffers).