Hauke Mehrtens af3c9b74e1 mbedtls: update to version 2.28.2
Changelog: https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.2
This release of Mbed TLS provides bug fixes and minor enhancements. This
release includes fixes for security issues.

Fixes the following CVEs:
* CVE-2022-46393: Fix potential heap buffer overread and overwrite in
DTLS if MBEDTLS_SSL_DTLS_CONNECTION_ID is enabled and
MBEDTLS_SSL_CID_IN_LEN_MAX > 2 * MBEDTLS_SSL_CID_OUT_LEN_MAX.

* CVE-2022-46392: An adversary with access to precise enough information
about memory accesses (typically, an untrusted operating system
attacking a secure enclave) could recover an RSA private key after
observing the victim performing a single private-key operation if the
window size used for the exponentiation was 3 or smaller.

Signed-off-by: Hauke Mehrtens <hauke@hauke-m.de>
2022-12-31 03:19:58 +01:00
..
2022-11-05 14:07:46 +00:00
2021-02-14 19:38:15 +01:00
2022-09-06 16:36:40 +01:00
2022-10-02 20:22:54 +02:00
2021-02-14 19:38:15 +01:00
2022-07-04 20:37:41 +02:00
2022-09-06 16:36:44 +01:00
2022-09-06 16:36:45 +01:00
2022-11-12 13:15:16 +01:00
2022-09-06 16:36:41 +01:00
2022-09-06 16:36:48 +01:00
2022-09-06 16:36:48 +01:00
2022-07-10 19:07:47 +02:00
2022-12-17 20:24:46 +01:00
2022-09-07 04:22:40 +01:00
2022-12-31 03:19:58 +01:00
2022-10-19 21:40:23 +02:00
2022-09-06 16:34:26 +01:00
2022-11-05 14:07:46 +00:00
2022-04-16 14:02:11 +02:00
2022-10-02 20:22:54 +02:00
2022-10-23 18:16:22 +02:00
2022-11-13 20:47:57 +01:00