# Silicon Labs Security Advisory A-00000425 : Security Advisory for buffer-read overflow in certain DTLS Server configurations of Mbed TLS Flags: MCU CVSS Severity: High CVSS Base Score: 9.1 Critical CVSS Temporal Score: 8.3 High CVSS String: [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H/E:P/RL:W/RC:C](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H/E:P/RL:W/RC:C) ## Product Impact | Product | Impacted Version | Main SDK | Impacted Version | CVE | | --- | --- | --- | --- | --- | | Mbed TLS | 3.1.x and earlier | GSDK | 4.1.1 and earlier | [CVE-2022-35409](https://nvd.nist.gov/vuln/detail/CVE-2022-35409) | ### Source Product Impact Details - Only EFR32, EFM32, EZR32 SoCs and modules that run application code built with Gecko SDK 4.1.1 and earlier which are: operating as a DTLS Server, with SL_MBEDTLS_SSL_IN_CONTENT_LEN decreased below the safe, default values set in Gecko SDK - Notes: - Configuration of IoT end nodes as DTLS servers is uncommon in current deployments, and devices not configured to operate as DTLS servers are not susceptible to the vulnerability described in this document. - Systems using the default values of SL_MBEDTLS_SSL_IN_CONTENT_LEN set in Silicon Labs’ Gecko SDK aren’t vulnerable. - Devices configured as DTLS servers with MBEDTLS_SSL_DTLS_CLIENT_PORT_REUSE disabled are not susceptible to the vulnerability described in this document, however, be aware that this option is enabled by default in Gecko SDK ## Description - Vulnerability [CVE-2022-35409](https://nvd.nist.gov/vuln/detail/CVE-2022-35409) in Mbed TLS <3.2.0 causes a DTLS server to respond to DTLS ClientHello packets with an invalid session cookie length, potentially leading to a heap-based data-read overflow of up to 255 bytes. - The read overflow can cause a DTLS server to crash or disclose information based on error responses. The default value of MBEDTLS_SSL_IN_CONTENT_LEN is configured to exceed the threshold that would cause this error, and only configurations in which the default values have been changed are susceptible to this vulnerability. For more information on safe minimums, see the Fix/Work Around section of this document. - The default cookie handler, mbedtls_ssl_cookie_check will not read the cookie if its length is not the expected size (28 bytes if SHA-256 is enabled), further limiting the configurations to which this vulnerability is applicable. - The vulnerability requires Client Port Reuse to be enabled in order to cause the server to overrun the input buffer by the requested session cookie length. Client Port Reuse improves DTLS performance for reconnecting clients, but this feature is not necessary for DTLS server operation and can be safely disabled. ### Fix/Workaround - No action is required unless all three of the following statements are true: 1. You are operating a DTLS Server using an affected version of Mbed TLS 2. You leave MBEDTLS_SSL_DTLS_CLIENT_PORT_REUSE enabled 3. You decrease the default, safe, values of SL_MBEDTLS_SSL_IN_CONTENT_LEN in Gecko SDK - If you are running a DTLS Server with Client Port Reuse enabled, avoid modifying Gecko SDK’s default SL_MBEDTLS_SSL_IN_CONTENT_LEN, unless modification is strictly necessary, and when reducing SL_MBEDTLS_SSL_IN_CONTEN_LEN, never reduce its value below these minimum safe thresholds: - Fewer than 210 bytes while using the default cookie-check function, mbedtls_ssl_cookie_check or - Fewer than 571 bytes while using a custom cookie check function While the current version of Gecko SDK contains a version of Mbed TLS potentially impacted by this vulnerability, Gecko SDK will be updated in a future release, anticipated no later than 23Q2, to include a fixed version of Mbed TLS. In order to mitigate this vulnerability before that time, customers needing a DTLS server can use one of the following work arounds: - Disabling MBEDTLS_SSL_DTLS_CLIENT_PORT_REUSE, which is enabled by default in Gecko SDK, prevents the vulnerability described in this document, at the cost of modest DTLS performance loss. To disable Client Port Reuse in a DTLS server built with Gecko SDK, complete the following steps: - Navigate to \/ \/config/mbedtls_config.h for your project, where \ is typically SimplicityStudio/v5_workspace under your home directory for Simplicity Studio 5, and \ is the name of your project - Locate and comment-out the following line: #define MBEDTLS_SSL_DTLS_CLIENT_PORT_REUSE - ‘Clean Project’ and then rebuild your application with Client Port Reuse disabled - Finally, as a workaround before the official GSDK release, Mbed TLS 3.1.0 can be manually updated to version 3.2.0 or greater to prevent the vulnerability described in this document. Please note that until the official GSDK release, Mbed TLS 3.2.0 will not have been fully tested through Silicon Labs SQA and there may be unintended consequences. However, If you accept the associated risks, this workaround can be achieved via the following steps: - Download the latest Mbed TLS release at github (3.2.1 at the time of this writing) - Copy the contents of the new library into the Gecko SDK mbedtls directory included in your release (for v 4.1.1, this is located by default in your user’s home directory under: SimplicityStudio/SDKs/gecko_sdk/util/third_party/crypto/mbedtls) - Overwrite the existing contents, but do not delete any files or folders before performing the copy - ‘Clean Project’ and then rebuild your application with the new mbedTLS library - The mbedtls/include/mbedtls/build_info.h file will contain the version number of your mbedTLS installation ## Attribution ## Revision History | Rev | Date | Description of Changes | | --- | --- | --- | | 1.0 | 2022-SEP-15 | Initial publication | ## Additional Resources - Security policy: [https://www.silabs.com/security](https://www.silabs.com/security) - Technical support: [https://www.silabs.com/support](https://www.silabs.com/support)