An issue was discovered in Mbed TLS 3.6 before 3.6.1. A stack buffer overflow in mbedtls_ecdsa_der_to_raw() and mbedtls_ecdsa_raw_to_der() can occur when the bits parameter is larger than the largest supported curve. In some configurations with PSA disabled, all values of bits are affected. (This never happens in internal library calls, but can affect applications that call these functions directly.)
The vulnerability occurs in the mbedtls_ecdsa_der_to_raw() and mbedtls_ecdsa_raw_to_der() functions when the 'bits' parameter passed by the application is larger than the size of the largest supported elliptic curve. In configurations with PSA (Platform Security Architecture) interface disabled, the issue affects all values of the 'bits' parameter. Stack overflow occurs when the application calls these functions directly – the library internally never calls these functions in a vulnerable manner. An attacker who can control the 'bits' parameter value or input data processed by the application can overwrite the stack memory.
An attacker can trigger arbitrary code execution (RCE) in the context of the process using the library or cause its crash. In case of successful exploitation, it is also possible to compromise the confidentiality and integrity of processed data.
Mbed TLS should be updated to version 3.6.1 or later. Detailed information is available in the vendor's security advisory: https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2024-08-2/
Arm Mbed TLS version 3.6 before 3.6.1, particularly applications that directly call mbedtls_ecdsa_der_to_raw() or mbedtls_ecdsa_raw_to_der() functions; in configurations with PSA disabled, the scope of vulnerability is broader.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HTrustedfirmware Mbed Tls
APPTrustedfirmware3.6.0
Related vulnerabilities
RCE przez deserializację kontekstu SSL w Mbed TLS
Arm Mbed TLS: podszywanie się pod klienta przy wznawianiu sesji TLS 1.3
Buffer overflow w eksporcie klucza publicznego FFDH w Mbed TLS i TF-PSA-Crypto
Buffer underrun w Mbed TLS podczas zapisu nieprzezroczystej pary kluczy
Arm Mbed TLS: błąd weryfikacji certyfikatu klienta w TLS 1.3