AZL-27649

    Dashboard / Vulnerabilities / AZL-27649

    AZL-27649

    Published: 17 Jul 2023Last Modified: 21 Apr 2026
    Upstream:

    Summary: CVE-2023-3724 affecting package mariadb for versions less than 10.6.9-3.cm2

    Details: If a TLS 1.3 client gets neither a PSK (pre shared key) extension nor a KSE (key share extension) when connecting to a malicious server, a default predictable buffer gets used for the IKM (Input Keying Material) value when generating the session master secret. Using a potentially known IKM value when generating the session master secret key compromises the key generated, allowing an eavesdropper to reconstruct it and potentially allowing access to or meddling with message contents in the session. This issue does not affect client validation of connected servers, nor expose private key information, but could result in an insecure TLS 1.3 session when not controlling both sides of the connection. wolfSSL recommends that TLS 1.3 client side users update the version of wolfSSL used. 

    Affected packages

    Package

    Name: mariadb

    Purl: pkg:rpm/azure-linux/mariadb

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -10.6.9-3.cm2

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    AZL-27649 | CVE-DB