PT-2022-6102 · Arm+2 · Mbed Tls+2

Sharad Sinha

+3

·

Published

2022-12-15

·

Updated

2025-08-21

·

CVE-2022-46393

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mbed TLS versions prior to 2.28.2 Mbed TLS versions 3.x prior to 3.3.0
Description A potential heap-based buffer overflow and heap-based buffer over-read exists in DTLS if MBEDTLS SSL DTLS CONNECTION ID is enabled and MBEDTLS SSL CID IN LEN MAX is greater than 2 times MBEDTLS SSL CID OUT LEN MAX. This issue can be exploited by a remote attacker to overwrite data in the buffer memory and potentially recover a closed RSA key.
Recommendations For Mbed TLS versions prior to 2.28.2, update to version 2.28.2 or later. For Mbed TLS versions 3.x prior to 3.3.0, update to version 3.3.0 or later. As a temporary workaround, consider disabling the MBEDTLS SSL DTLS CONNECTION ID feature until a patch is available. Restrict access to DTLS connections where MBEDTLS SSL CID IN LEN MAX is greater than 2 times MBEDTLS SSL CID OUT LEN MAX to minimize the risk of exploitation.

Fix

Out of bounds Read

Memory Corruption

Weakness Enumeration

Related Identifiers

ALT-PU-2022-3348
ALT-PU-2023-4980
ALT-PU-2024-2404
ALT-PU-2025-10462
BDU:2023-00041
CVE-2022-46393
OPENSUSE-SU-2022:10257-1
OPENSUSE-SU-2024:12581-1

Affected Products

Alt Linux
Mbed Tls
Red Os