CVE-2023-39908

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
14/08/2023
Last modified:
25/08/2023

Description

The PKCS11 module of the YubiHSM 2 SDK through 2023.01 does not properly validate the length of specific read operations on object metadata. This may lead to disclosure of uninitialized and previously used memory.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:yubico:yubihsm_2_sdk:*:*:*:*:*:*:*:* 2023.08 (excluding)