Candidate: CVE-2021-45451 PublicDate: 2021-12-21 07:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45451 https://github.com/ARMmbed/mbedtls/releases/tag/v3.1.0 Description: In Mbed TLS before 3.1.0, psa_aead_generate_nonce allows policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N [7.5 HIGH] Patches_mbedtls: upstream_mbedtls: needs-triage trusty_mbedtls: ignored (out of standard support) xenial_mbedtls: ignored (out of standard support) bionic_mbedtls: needs-triage focal_mbedtls: needs-triage hirsute_mbedtls: ignored (reached end-of-life) impish_mbedtls: needs-triage jammy_mbedtls: needs-triage devel_mbedtls: needs-triage