Medium severity4.9NVD Advisory· Published Jul 14, 2021· Updated Jun 17, 2026
CVE-2021-24119
CVE-2021-24119
Description
In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments that can be single stepped, especially Intel SGX.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8- Trusted Firmware/Mbed TLSdescription
- osv-coords6 versionspkg:rpm/opensuse/mbedtls-2&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/mbedtls-3&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/mbedtls&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/mbedtls&distro=openSUSE%20Leap%2015.3pkg:rpm/suse/mbedtls&distro=SUSE%20Package%20Hub%2015%20SP2pkg:rpm/suse/mbedtls&distro=SUSE%20Package%20Hub%2015%20SP3
< 2.27.0-2.1+ 5 more
- (no CPE)range: < 2.27.0-2.1
- (no CPE)range: < 3.6.6-1.1
- (no CPE)range: < 2.16.9-lp152.2.6.1
- (no CPE)range: < 2.16.9-bp153.2.5.1
- (no CPE)range: < 2.16.9-bp152.2.6.1
- (no CPE)range: < 2.16.9-bp153.2.5.1
Patches
Vulnerability mechanics
References
7- github.com/ARMmbed/mbedtls/releasesnvdRelease NotesThird Party Advisory
- github.com/UzL-ITS/util-lookup/blob/main/cve-vulnerability-publication.mdnvdRelease NotesThird Party Advisory
- lists.debian.org/debian-lts-announce/2021/11/msg00021.htmlnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2022/12/msg00036.htmlnvdMailing ListThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DRRVY7DMTX3ECFNZKDYTSFEG5AI2HBC6/nvdMailing ListThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EYJW7HAW3TDV2YMDFYXP3HD6WRQRTLJW/nvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2025/06/msg00034.htmlnvd
News mentions
0No linked articles in our index yet.