Description
In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected. | |
| Weaknesses | CWE-385 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-01T20:00:06.815Z
Reserved: 2025-12-01T00:00:00.000Z
Link: CVE-2025-66442
Updated: 2026-04-01T19:58:42.109Z
Status : Received
Published: 2026-04-01T20:16:22.107
Modified: 2026-04-01T20:16:22.107
Link: CVE-2025-66442
No data.
OpenCVE Enrichment
No data.
Weaknesses