CVE-2024-28960

Source
https://cve.org/CVERecord?id=CVE-2024-28960
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-28960.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-28960
Downstream
Related
Published
2024-03-29T06:15:07.270Z
Modified
2026-03-15T14:51:19.774148Z
Severity
  • 8.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N CVSS Calculator
Summary
[none]
Details

An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory.

References

Affected packages

Git / github.com/armmbed/mbed-crypto

Affected ranges

Type
GIT
Repo
https://github.com/armmbed/mbed-crypto
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.1.0"
        }
    ]
}
Type
GIT
Repo
https://github.com/armmbed/mbedtls
Events
Database specific
{
    "versions": [
        {
            "introduced": "2.1.8"
        },
        {
            "fixed": "2.28.8"
        },
        {
            "introduced": "3.0.0"
        },
        {
            "fixed": "3.6.0"
        }
    ]
}

Affected versions

mbedcrypto-0.*
mbedcrypto-0.1.0b
mbedcrypto-0.1.0b2
mbedcrypto-1.*
mbedcrypto-1.0.0
mbedcrypto-1.0.0d0
mbedcrypto-1.0.0d1
mbedcrypto-1.0.0d2
mbedcrypto-1.0.0d3
mbedcrypto-1.0.0d4
mbedcrypto-1.0.0d5
mbedcrypto-1.0.0d6
mbedcrypto-1.0.0d7
mbedcrypto-1.1.0
mbedcrypto-1.1.0d0
mbedcrypto-1.1.0d1
mbedcrypto-1.1.0d2
mbedcrypto-1.1.1
mbedcrypto-2.*
mbedcrypto-2.0.0
mbedcrypto-2.0.0d0
mbedcrypto-2.0.0d1
mbedcrypto-2.0.0d2
mbedcrypto-2.1.0d0
mbedcrypto-3.*
mbedcrypto-3.0.0
mbedcrypto-3.0.0d0
mbedcrypto-3.0.1
mbedcrypto-3.1.0
mbedtls-3.*
mbedtls-3.0.0
mbedtls-3.1.0
mbedtls-3.2.0
mbedtls-3.2.1
mbedtls-3.3.0
mbedtls-3.4.0
mbedtls-3.4.1
mbedtls-3.5.0
mbedtls-3.5.1
mbedtls-3.5.2
psa-crypto-api-1.*
psa-crypto-api-1.0-beta1
psa-crypto-api-1.0-beta2
psa-crypto-api-1.0-beta3
v3.*
v3.0.0
v3.1.0
v3.2.0
v3.2.1
v3.3.0
v3.4.0
v3.4.1
v3.5.0
v3.5.1
v3.5.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-28960.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "38"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "39"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "40"
            }
        ]
    }
]