Fix impact evaluation

Signed-off-by: Manuel Pégourié-Gonnard <[email protected]>
This commit is contained in:
Manuel Pégourié-Gonnard
2022-06-20 21:12:29 +02:00
committed by Manuel Pégourié-Gonnard
parent 22e84de971
commit 19a567ba43
@@ -2,6 +2,5 @@ Security
* Fix a potential heap buffer overread in TLS 1.2 server-side when
MBEDTLS_USE_PSA_CRYPTO is enabled, an opaque key (created with
mbedtls_pk_setup_opaque()) is provisioned, and a static ECDH ciphersuite
is selected. This may result in an application crash. No path to
information leak has been identified.
is selected. This may result in an application crash or potentially an
information leak.