CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other par...Show more |
In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected. |
2Arm Trustedfirmware3Mbed Tls Tf Psa CryptoTf Psa CryptoJun 17, 2026 Apr 1, 2026 N/A· v4 6.7 MEDIUM· v3 N/A· v2 An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG). |
3Arm LinaroTrustedfirmware5Mbed Tls Mbed TlsTf Psa Crypto+2 moreJun 17, 2026 Apr 1, 2026 N/A· v4 7.7 HIGH· v3 N/A· v2 Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG). |
2Arm Trustedfirmware4Mbed Tls Mbed TlsTf Psa Crypto+1 moreJun 17, 2026 Apr 1, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys. |