Mbed-TLS.mbedtls is vulnerable to Stack-based Buffer Overflow
81
High Risk
In Mbed TLS 3.6.0, the functions mbedtls_ecdsa_der_to_raw() and mbedtls_ecdsa_raw_to_der() are vulnerable to a stack buffer overflow if the bits argument exceeds the maximum curve size, due to missing validation. When MBEDTLS_PSA_CRYPTO_C is disabled, these functions may use a zero-sized internal buffer, leading to overflows even with valid input. This affects applications that invoke these functions on attacker-controlled input, allowing an attacker to trigger a buffer overflow by manipulating the declared curve bit size.
You are affected if you are using a version that falls within the vulnerable range.
Mbed-TLS.mbedtls is vulnerable to Stack-based Buffer Overflow in versions 3.6.0 - 3.6.0.
Upgrade the Mbed-TLS.mbedtls library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant