CVE-2024-45157

Name
CVE-2024-45157
Description
An issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which the user-selected algorithm is not used. Unlike previously documented, enabling MBEDTLS_PSA_HMAC_DRBG_MD_TYPE does not cause the PSA subsystem to use HMAC_DRBG: it uses HMAC_DRBG only when MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG and MBEDTLS_CTR_DRBG_C are disabled.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
https://mbed-tls.readthedocs.io/en/latest/security-advisories/
https://github.com/Mbed-TLS/mbedtls/releases/
https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2024-08-1/

Match rules

CPE URI Source package Min version Max version
n/a == n/a == n/a
cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:* mbed_tls >= 2.26.0 < 2.28.9
cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:* mbed_tls >= 3.2.0 < 3.6.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
mbedtls2 edge-community 2.28.10-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
mbedtls2 3.23-community 2.28.10-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
mbedtls2 3.22-community 2.28.10-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
mbedtls2 3.21-community 2.28.10-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
mbedtls edge-main 3.6.1-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
mbedtls 3.22-main 3.6.1-r0 None fixed
mbedtls 3.21-main 3.6.1-r0 None fixed
mbedtls 3.20-main 3.6.1-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
mbedtls 3.19-main 2.28.9-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
mbedtls 3.18-main 2.28.9-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
mbedtls 3.17-main 2.28.9-r0 Natanael Copa <ncopa@alpinelinux.org> fixed