Logo
componentmbedtls
Name
mbedtls
Version
3.6.6
Type
library
Description
Lightweight crypto and SSL/TLS library
Licenses
Apache-2.0 | GPL-2.0-or-later
PURL
-
CPE
cpe:2.3:*:*:mbed_tls:3.6.6:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
kirkstone
3.5.2
scarthgap
3.6.6

Vulnerabilities#


Name
Analysis
Description
Exploitable
In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected.