CVE-2025-66442

Published: Apr 01, 2026 Last Modified: Apr 01, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 5,1
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Attack Vector: local
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: none
Availability: none

Description

AI Translation Available

In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected.

385

Covert Timing Channel

Incomplete
Common Consequences
Security Scopes Affected:
Confidentiality Other
Potential Impacts:
Read Application Data Other
Applicable Platforms
All platforms may be affected
View CWE Details
https://github.com/Mbed-TLS/mbedtls/releases
https://github.com/Mbed-TLS/TF-PSA-Crypto/releases
https://mbed-tls.readthedocs.io/en/latest/security-advisories/
https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-…