Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 03 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arm
Arm mbed Tls Arm tf-psa-crypto |
|
| CPEs | cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:* cpe:2.3:a:arm:tf-psa-crypto:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Arm
Arm mbed Tls Arm tf-psa-crypto |
Fri, 03 Apr 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mbed-tls
Mbed-tls mbedtls Mbed-tls tf-psa-crypto |
|
| Vendors & Products |
Mbed-tls
Mbed-tls mbedtls Mbed-tls tf-psa-crypto |
Thu, 02 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | mbedtls: Mbed TLS and TF-PSA-Crypto: Information disclosure via compiler-induced timing side channel | |
| Weaknesses | CWE-733 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected. | |
| Weaknesses | CWE-385 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-01T20:00:06.815Z
Reserved: 2025-12-01T00:00:00.000Z
Link: CVE-2025-66442
Updated: 2026-04-01T19:58:42.109Z
Status : Analyzed
Published: 2026-04-01T20:16:22.107
Modified: 2026-04-03T20:04:38.487
Link: CVE-2025-66442
OpenCVE Enrichment
Updated: 2026-04-07T08:07:48Z