CVE-2022-46393

CRITICAL

Mbed TLS <2.28.2,3.x <3.3.0 - Buffer Overflow

Title source: llm
STIX 2.1

Description

An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow and heap-based buffer over-read in DTLS if MBEDTLS_SSL_DTLS_CONNECTION_ID is enabled and MBEDTLS_SSL_CID_IN_LEN_MAX > 2 * MBEDTLS_SSL_CID_OUT_LEN_MAX.

Scores

CVSS v3 9.8
EPSS 0.0082
EPSS Percentile 74.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-125 CWE-787
Status published
Products (3)
arm/mbed_tls < 2.28.2
fedoraproject/fedora 36
fedoraproject/fedora 37
Published Dec 15, 2022
Tracked Since Feb 18, 2026