VYPR
Medium severity5.1NVD Advisory· Published Apr 1, 2026· Updated Apr 3, 2026

CVE-2025-66442

CVE-2025-66442

Description

In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected.

Affected products

2
  • cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:*
    Range: <=4.0.0
  • cpe:2.3:a:arm:tf-psa-crypto:*:*:*:*:*:*:*:*
    Range: <=1.0.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.