CVE-2024-28960: High severity Mbed TLS vulnerability
An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0 and Mbed Crypto. The PSA Crypto API mishandles shared memory.
Other sources
An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28960?
CVE-2024-28960 has been assigned a severity rating that indicates it can lead to significant security risks due to mishandling of shared memory.
How do I fix CVE-2024-28960?
To resolve CVE-2024-28960, update Mbed TLS to version 2.28.8 or later, or version 3.6.0 or later.
What versions of Mbed TLS are affected by CVE-2024-28960?
Mbed TLS versions from 2.18.0 up to 2.28.8 and from 3.0.0 up to 3.6.0 are affected by CVE-2024-28960.
Is Mbed Crypto affected by CVE-2024-28960?
Yes, Mbed Crypto is affected by the vulnerability described in CVE-2024-28960.
What should I do if I cannot update Mbed TLS immediately to fix CVE-2024-28960?
If immediate updates are not possible, consider implementing additional security measures to mitigate potential risks associated with CVE-2024-28960.