Name
CVE-2024-28836
Description
An issue was discovered in Mbed TLS 3.5.x before 3.6.0. When negotiating the TLS version on the server side, it can fall back to the TLS 1.2 implementation of the protocol if it is disabled. If the TLS 1.2 implementation was disabled at build time, a TLS 1.2 client could put a TLS 1.3-only server into an infinite loop processing a TLS 1.2 ClientHello, resulting in a denial of service. If the TLS 1.2 implementation was disabled at runtime, a TLS 1.2 client can successfully establish a TLS 1.2 connection with the server.
CWEs
Published Date
Updated Date
Workaround
-
Advisories
Analysis#
Vulnerability Ratings#
5.4
CVSSv31
NaN
other
Others affected components#
Resolved with patches#
mbedtls (yocto:kirkstone)
#
Title
Author
Resolve
1
Merge pull request #1177 from
Janos Follath <janos.follath@arm.com>
CVE-2024-28755
CVE-2024-28836
mbedtls (yocto:kirkstone)
#
Title
Author
Resolve
1
Merge pull request #1177 from
Janos Follath <janos.follath@arm.com>
CVE-2024-28755
CVE-2024-28836