New vulnerabilities found in ARM mbed TLS
guidovranken.wordpress.com
guidovranken.wordpress.com
Keep them coming, I'm glad that so many of us who use mbedTLS are reporting these little issues and getting a better library (with an excellent track record of very few serious problems).
Arguably, the real bug is that these crypto libraries even try to represent negative numbers at all in the first place. In ring I'm close to removing all support for negative numbers.
Now if you have deployed this to millions of iot devices without a eorkbg firmware upgrade system, tough luck buddy :(