In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected.
Metrics
Affected Vendors & Products
References
History
Fri, 03 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arm
Arm mbed Tls Arm tf-psa-crypto |
|
| CPEs | cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:* cpe:2.3:a:arm:tf-psa-crypto:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Arm
Arm mbed Tls Arm tf-psa-crypto |
Fri, 03 Apr 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mbed-tls
Mbed-tls mbedtls Mbed-tls tf-psa-crypto |
|
| Vendors & Products |
Mbed-tls
Mbed-tls mbedtls Mbed-tls tf-psa-crypto |
Thu, 02 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | mbedtls: Mbed TLS and TF-PSA-Crypto: Information disclosure via compiler-induced timing side channel | |
| Weaknesses | CWE-733 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected. | |
| Weaknesses | CWE-385 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-04-01T00:00:00.000Z
Updated: 2026-04-01T20:00:06.815Z
Reserved: 2025-12-01T00:00:00.000Z
Link: CVE-2025-66442
Updated: 2026-04-01T19:58:42.109Z
Status : Analyzed
Published: 2026-04-01T20:16:22.107
Modified: 2026-04-03T20:04:38.487
Link: CVE-2025-66442