-
Notifications
You must be signed in to change notification settings - Fork 8.2k
Closed
Labels
LTSLong term release branch relatedLong term release branch relatedarea: SecuritySecuritySecuritybugThe issue is a bug, or the PR is fixing a bugThe issue is a bug, or the PR is fixing a bugpriority: highHigh impact/importance bugHigh impact/importance bug
Milestone
Description
Describe the bug
mbedTLS 2.26 used on Zephyr LTS contains several vulnerabilities:
https://www.cvedetails.com/cve/CVE-2021-45450/
https://www.cvedetails.com/cve/CVE-2022-35409/
https://www.cvedetails.com/cve/CVE-2022-46392/
https://www.cvedetails.com/cve/CVE-2022-46393/
Expected behavior
Use an updated version that address known issues.
Impact
Products using this version may be exploited.
Additional context
https://www.cvedetails.com/vulnerability-list/vendor_id-15698/product_id-32568/ARM-Mbed-Tls.html
Metadata
Metadata
Labels
LTSLong term release branch relatedLong term release branch relatedarea: SecuritySecuritySecuritybugThe issue is a bug, or the PR is fixing a bugThe issue is a bug, or the PR is fixing a bugpriority: highHigh impact/importance bugHigh impact/importance bug