Low severity3.7NVD Advisory· Published Mar 15, 2023· Updated Jun 17, 2026
CVE-2023-26084
CVE-2023-26084
Description
The armv8_dec_aes_gcm_full() API of Arm AArch64cryptolib before 86065c6 fails to the verify the authentication tag of AES-GCM protected data, leading to a man-in-the-middle attack. This occurs because of an improperly initialized variable.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:arm:aarch64cryptolib:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:arm:aarch64cryptolib:*:*:*:*:*:*:*:*range: <2023-02-20
- (no CPE)range: <86065c6
- Arm/AArch64cryptolibdescription
Patches
Vulnerability mechanics
References
1- github.com/ARM-software/AArch64cryptolib/security/advisories/GHSA-47c6-7x5x-r74gnvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.