High severity8.2NVD Advisory· Published Mar 29, 2024· Updated Jun 17, 2026
CVE-2024-28960
CVE-2024-28960
Description
An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10cpe:2.3:a:arm:mbed_crypto:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:arm:mbed_crypto:*:*:*:*:*:*:*:*range: <=3.1.0
- (no CPE)
- (no CPE)range: unknown
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
8- github.com/Mbed-TLS/mbedtls-docs/blob/main/security-advisories/mbedtls-security-advisory-2024-03.mdnvdVendor Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5YE3QRREGJC6K34JD4LZ5P3IALNX4QYY/nvdMailing ListThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6UZNBMKYEV2J5DI7R4BQGL472V7X3WJY/nvdMailing ListThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NCDU52ZDA7TX3HC5JCU6ZZIJQOPTNBK6/nvdMailing ListThird Party Advisory
- mbed-tls.readthedocs.io/en/latest/tech-updates/security-advisories/nvdVendor Advisory
- lists.fedoraproject.org/archives/list/[email protected]/message/5YE3QRREGJC6K34JD4LZ5P3IALNX4QYY/nvd
- lists.fedoraproject.org/archives/list/[email protected]/message/6UZNBMKYEV2J5DI7R4BQGL472V7X3WJY/nvd
- lists.fedoraproject.org/archives/list/[email protected]/message/NCDU52ZDA7TX3HC5JCU6ZZIJQOPTNBK6/nvd
News mentions
0No linked articles in our index yet.