Wind River Support Network

HomeDefectsLIN1021-5065
Fixed

LIN1021-5065 : Security Advisory - mbedtls - CVE-2021-36647

Created: Jan 17, 2023    Updated: Mar 1, 2023
Resolved Date: Mar 1, 2023
Found In Version: 10.21.20.1
Fix Version: 10.21.20.17
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS all versions before 3.0.0, 2.27.0 or 2.16.11 allows attackers with access to precise enough timing and memory access information (typically an untrusted operating system attacking a secure enclave such as SGX or the TrustZone secure world) to recover the private keys used in RSA.

CREATE(Triage):(User=admin) CVE-2021-36647 (https://nvd.nist.gov/vuln/detail/CVE-2021-36647)

CVEs


Live chat
Online