PT-2021-24238 · Mbed Tls+1 · Mbed Tls+1

Published

2021-12-18

·

Updated

2025-08-21

·

CVE-2021-45450

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Mbed TLS versions prior to 2.28.0 Mbed TLS versions 3.x prior to 3.1.0
Description: The issue allows policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application, specifically affecting the psa cipher generate iv and psa cipher encrypt functions.
Recommendations: For Mbed TLS versions prior to 2.28.0, update to version 2.28.0 or later. For Mbed TLS versions 3.x prior to 3.1.0, update to version 3.1.0 or later. As a temporary workaround, consider restricting access to the psa cipher generate iv and psa cipher encrypt functions until a patch is available.

Fix

Use of a Broken Cryptographic Algorithm

Weakness Enumeration

Related Identifiers

ALT-PU-2021-3553
ALT-PU-2022-2561
ALT-PU-2025-10462
CVE-2021-45450
OPENSUSE-SU-2024:11752-1

Affected Products

Alt Linux
Mbed Tls