CVE-2025-66442
MEDIUM
5,1
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Attack Vector: local
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: none
Availability: none
Description
AI Translation Available
In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected.
385
Covert Timing Channel
IncompleteCommon Consequences
Security Scopes Affected:
Confidentiality
Other
Potential Impacts:
Read Application Data
Other
Applicable Platforms
All platforms may be affected
https://github.com/Mbed-TLS/mbedtls/releases
https://github.com/Mbed-TLS/TF-PSA-Crypto/releases
https://mbed-tls.readthedocs.io/en/latest/security-advisories/
https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-…