MGASA-2024-0146

Source
https://advisories.mageia.org/MGASA-2024-0146.html
Import Source
https://advisories.mageia.org/MGASA-2024-0146.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2024-0146
Related
Published
2024-04-25T16:00:30Z
Modified
2024-04-25T15:43:19Z
Summary
Updated mbedtls packages fix security vulnerability
Details

An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory. (CVE-2024-28960)

References
Credits

Affected packages

Mageia:9 / mbedtls

Package

Name
mbedtls
Purl
pkg:rpm/mageia/mbedtls?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.28.8-1.mga9

Ecosystem specific

{
    "section": "core"
}