PT-2023-20477 · Arm · Arm Aarch64Cryptolib

Milinjpatel

+1

·

Published

2023-03-15

·

Updated

2025-02-27

·

CVE-2023-26084

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Arm AArch64cryptolib versions before 86065c6
Description The issue concerns the armv8 dec aes gcm full() API, which fails to verify the authentication tag of AES-GCM protected data. This failure is due to an improperly initialized variable, leading to a potential man-in-the-middle attack.
Recommendations For Arm AArch64cryptolib versions before 86065c6, update to a version after 86065c6 to resolve the issue. As a temporary workaround, consider restricting the use of the armv8 dec aes gcm full() API until a patch is available.

Fix

Improper Initialization

Weakness Enumeration

Related Identifiers

CVE-2023-26084
GHSA-47C6-7X5X-R74G

Affected Products

Arm Aarch64Cryptolib