Integer Overflow Vulnerability in Yubico YubiHSM 2 SDK
CVE-2021-32489
What is CVE-2021-32489?
An integer overflow vulnerability has been discovered in the '_send_secure_msg()' function of Yubico's yubihsm-shell, which is part of the YubiHSM 2 SDK. This issue arises when the function fails to properly validate the embedded length field of an authenticated message coming from the device. Specifically, an accepted response message with a length of 8 can lead to an integer overflow, causing the CRYPTO_cbc128_decrypt function in OpenSSL to operate on an undersized buffer, which in turn results in a segmentation fault. This flaw poses potential risks for applications utilizing Yubico’s solutions for secure message processing.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
