Wind River Support Network

HomeDefectsLIN1021-840
Fixed

LIN1021-840 : Security Advisory - mbedtls - CVE-2021-24119

Created: Jul 18, 2021    Updated: Sep 22, 2023
Resolved Date: Sep 22, 2023
Found In Version: 10.21.20.1
Fix Version: 10.21.20.19
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments that can be single stepped, especially Intel SGX.

CREATE(Triage):(User=admin) CVE-2021-24119 (https://nvd.nist.gov/vuln/detail/CVE-2021-24119)

CVEs


Live chat
Online