Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may be able to extract an AES key from a multithreaded program, or perform a GCM forgery.
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Vulnerability Type
编译器优化对安全关键代码的移除或修改
Vulnerability Title
Mbed TLS 安全漏洞
Vulnerability Description
Mbed TLS是Mbed TLS开源的一个开源、可移植、易于使用、可读且灵活的 SSL 库。 Mbed TLS 3.6.4之前版本存在安全漏洞,该漏洞源于AESNI检测中的竞争条件,可能导致AES密钥泄露或GCM伪造。
CVSS Information
N/A
Vulnerability Type
N/A