High severity7.5NVD Advisory· Published Dec 21, 2021· Updated Jun 17, 2026
CVE-2021-45450
CVE-2021-45450
Description
In Mbed TLS before 2.28.0 and 3.x before 3.1.0, psa_cipher_generate_iv and psa_cipher_encrypt allow policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
- Mbed TLS/Mbed TLSdescription
- osv-coords2 versionspkg:rpm/opensuse/mbedtls-2&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/mbedtls-3&distro=openSUSE%20Tumbleweed
< 2.28.0-1.1+ 1 more
- (no CPE)range: < 2.28.0-1.1
- (no CPE)range: < 3.6.6-1.1
Patches
Vulnerability mechanics
References
5- github.com/ARMmbed/mbedtls/releases/tag/v2.28.0nvdRelease NotesThird Party Advisory
- github.com/ARMmbed/mbedtls/releases/tag/v3.1.0nvdRelease NotesThird Party Advisory
- security.gentoo.org/glsa/202301-08nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IL66WKJGXY5AXMTFE7QDMGL3RIBD6PX5/nvdMailing List
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TALJHOYAYSUJTLN6BYGLO4YJGNZUY74W/nvdMailing List
News mentions
0No linked articles in our index yet.