Wind River Support Network

HomeDefectsLIN1022-5482
Fixed

LIN1022-5482 : Security Advisory - mbedtls - CVE-2021-43666

Created: Sep 24, 2023    Updated: Sep 27, 2023
Resolved Date: Sep 24, 2023
Previous ID: LIN1021-6580
Found In Version: 10.22.33.3
Fix Version: 10.22.33.12
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Userspace

Description

A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an input password's length is 0.



CREATE(Triage):(User=admin) CVE-2021-43666 (https://nvd.nist.gov/vuln/detail/CVE-2021-43666)

CVEs


Live chat
Online