openwrt ▾
›
master ▾
›
vulnerability
›
CVE-2025-66442
Component Overview
Vulnerability Overview
Name
CVE-2025-66442
Source
NVD (
link
)
Debian (
link
)
Description
In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected.
CWEs
CWE-385
Published Date
Apr 1, 2026
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/Mbed-TLS/TF-PSA-Crypto/releases
Release Notes
https://github.com/Mbed-TLS/mbedtls/releases
Release Notes
https://mbed-tls.readthedocs.io/en/latest/security-advisories/
Vendor Advisory
https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-03-compiler-induced-constant-time-violations/
Vendor Advisory
Analysis
#
Affected Component
Analysis
mbedtls
Exploitable
Vulnerability Ratings
#
5.1
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
mbedtls
buildroot
2025.02.x
3.6.6
Exploitable
mbedtls
buildroot
master
3.6.6
Exploitable
mbedtls
openwrt
openwrt-25.12
3.6.6-r2
Exploitable