UBUNTU-CVE-2024-28960
Dashboard / Vulnerabilities / UBUNTU-CVE-2024-28960
Summary:
Details: An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory.
References: https://ubuntu.com/security/CVE-2024-28960, https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2024-03/, https://github.com/Mbed-TLS/mbedtls-docs/blob/main/security-advisories/mbedtls-security-advisory-2024-03.md, https://mbed-tls.readthedocs.io/en/latest/tech-updates/security-advisories/, https://www.cve.org/CVERecord?id=CVE-2024-28960, https://github.com/Mbed-TLS/mbedtls/issues/3266
Affected packages
Package
Name: mbedtls
Purl: pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=esm-apps/jammy
Affected ranges
Type: ECOSYSTEM
Events:
