Logo
componentmbedtls
Name
mbedtls
Version
3.6.6-r2
Type
library
Description
-
Licenses
-
PURL
-
CPE
cpe:2.3:a:arm:mbed_tls:3.6.6:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
master
3.6.6-r2

Patches#


#
Title
Author
Resolve
1
ssl: accept TLS 1.2 rsa_pss_rsae signature schemes
Viktor Sokolovskiy <maokaman@gmail.com>
2
Patch #2
Unknown
3
Patch #3
Unknown
4
ssl: narrow TLS 1.2 RSA-PSS handling and add interop coverage
Viktor Sokolovskiy <maokaman@gmail.com>

Vulnerabilities#


Name
Analysis
Description
Exploitable
In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected.