Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.
JLSEC-2025-226

An issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which the user-selected a...

JLSEC Published
Modified
Affected Packages
MbedTLS_jll >= 2.26.0+0, < 2.28.10+0
Aliases / Upstream
CVE-2024-45157

An issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which the user-selected algorithm is not used. Unlike previously documented, enabling MBEDTLSPSAHMACDRBGMDTYPE does not cause the PSA subsystem to use HMACDRBG: it uses HMACDRBG only when MBEDTLSPSACRYPTOEXTERNALRNG and MBEDTLSCTRDRBGC are disabled.

References