CVE-2025-66442

Published
View on NVD ↗
CVSS v3
5.1
MEDIUM
CVSS v2
N/A
Affected
2
PROJECTS

Description

In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected.

An open source, portable, easy to use, readable and flexible TLS library, and reference implementation of the PSA Cryptography API. Releases are on a varying cadence, typically around 3 - 6 months between releases.
GitHubGitHub
6.69K
Reference implementation of the PSA Cryptography API
GitHubGitHub
50