CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-45158

CVSS 9.8v3.1pub. 2024-09-05upd. 2026-06-05

An issue was discovered in Mbed TLS 3.6 before 3.6.1. A stack buffer overflow in mbedtls_ecdsa_der_to_raw() and mbedtls_ecdsa_raw_to_der() can occur when the bits parameter is larger than the largest supported curve. In some configurations with PSA disabled, all values of bits are affected. (This never happens in internal library calls, but can affect applications that call these functions directly.)

🤖 AI Analysis
How it works

The vulnerability occurs in the mbedtls_ecdsa_der_to_raw() and mbedtls_ecdsa_raw_to_der() functions when the 'bits' parameter passed by the application is larger than the size of the largest supported elliptic curve. In configurations with PSA (Platform Security Architecture) interface disabled, the issue affects all values of the 'bits' parameter. Stack overflow occurs when the application calls these functions directly – the library internally never calls these functions in a vulnerable manner. An attacker who can control the 'bits' parameter value or input data processed by the application can overwrite the stack memory.

Impact

An attacker can trigger arbitrary code execution (RCE) in the context of the process using the library or cause its crash. In case of successful exploitation, it is also possible to compromise the confidentiality and integrity of processed data.

Mitigation & patch

Mbed TLS should be updated to version 3.6.1 or later. Detailed information is available in the vendor's security advisory: https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2024-08-2/

Who is affected

Arm Mbed TLS version 3.6 before 3.6.1, particularly applications that directly call mbedtls_ecdsa_der_to_raw() or mbedtls_ecdsa_raw_to_der() functions; in configurations with PSA disabled, the scope of vulnerability is broader.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Trustedfirmware Mbed Tls

    APP
    Trustedfirmware
    3.6.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2026-34877CRITICAL9.8PL ✓same product

RCE przez deserializację kontekstu SSL w Mbed TLS

CVE-2026-34873CRITICAL9.1PL ✓same product

Arm Mbed TLS: podszywanie się pod klienta przy wznawianiu sesji TLS 1.3

CVE-2026-34875CRITICAL9.8PL ✓same product

Buffer overflow w eksporcie klucza publicznego FFDH w Mbed TLS i TF-PSA-Crypto

CVE-2024-49195CRITICAL9.8PL ✓same product

Buffer underrun w Mbed TLS podczas zapisu nieprzezroczystej pary kluczy

CVE-2024-45159CRITICAL9.8PL ✓same product

Arm Mbed TLS: błąd weryfikacji certyfikatu klienta w TLS 1.3