CVE-2024-28960: Arm Mbed Crypto

High severity, CVSS 8.2. EPSS: 0.8% chance of exploitation in the next 30 days.

An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory.

Affected products

  • Arm Mbed Crypto: up to and including 3.1.0
  • Arm Mbed TLS: from 2.1.8, before 2.28.8 (fixed in 2.28.8)
  • Fedoraproject Fedora: version 38 only; version 39 only; version 40 only
  • Trustedfirmware Mbed TLS: from 3.0.0, before 3.6.0 (fixed in 3.6.0)

Published 2024-03-29. Last modified 2026-06-17.