-
Couldn't load subscription status.
- Fork 8.1k
Closed
Labels
area: Networkingarea: SecuritySecuritySecuritybugThe issue is a bug, or the PR is fixing a bugThe issue is a bug, or the PR is fixing a bugpriority: highHigh impact/importance bugHigh impact/importance bug
Milestone
Description
There is a pretty obvious, blatant buffer overflow possibility in the mbedTLS codebase (2.6.0) used by Zephyr as of now. It was fixed in 2.7.0 by this commit: Mbed-TLS/mbedtls@0b7b83fd9 .
In the interest of establishing Zephyr as the secure codebase, we should upgrade included mbedTLS for the 1.11 release.
Metadata
Metadata
Assignees
Labels
area: Networkingarea: SecuritySecuritySecuritybugThe issue is a bug, or the PR is fixing a bugThe issue is a bug, or the PR is fixing a bugpriority: highHigh impact/importance bugHigh impact/importance bug