Skip to main content

CVE-2024-45157

Severity Medium
Score 5.1/10

Summary

An issue was discovered in Mbed TLS versions prior to 2.28.9, and 3.x prior to 3.6.1, in which the user-selected algorithm was not used. Unlike previously documented, enabling "MBEDTLS_PSA_HMAC_DRBG_MD_TYPE" does not cause the "PSA" subsystem to use "HMAC_DRBG:", it uses "HMAC_DRBG" only when "MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG" and "MBEDTLS_CTR_DRBG_C" are disabled.

  • HIGH
  • LOCAL
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • NONE

Advisory Timeline

  • Published