CVE-2024-45158

CRITICAL

Mbed TLS 3.6 - Stack-based Buffer Overflow in ECDSA DER Conversion Functions

Title source: llm
STIX 2.1

Description

An issue was discovered in Mbed TLS 3.6 before 3.6.1. A stack buffer overflow in mbedtls_ecdsa_der_to_raw() and mbedtls_ecdsa_raw_to_der() can occur when the bits parameter is larger than the largest supported curve. In some configurations with PSA disabled, all values of bits are affected. (This never happens in internal library calls, but can affect applications that call these functions directly.)

Scores

CVSS v3 9.8
EPSS 0.0068
EPSS Percentile 71.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-121
Status published
Products (1)
arm/mbed_tls 3.6.0
Published Sep 05, 2024
Tracked Since Feb 18, 2026