HomeDefectsLIN1022-14340
Fixed

LIN1022-14340 : Security Advisory - mbedtls - CVE-2025-27810

Created: Mar 24, 2025    Updated: Jan 14, 2026
Resolved Date: Jan 13, 2026
Found In Version: 10.22.33.1
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Userspace

Description

During the TLS handshake, the Finished message ensures that the handshake has not been tampered with by an active attacker. If a memory allocation fails or a cryptographic hardware driver returns an error at a specific point during the handshake, the Finished message will be incorrectly calculated to be the contents of uninitialized stack memory.

CVEs