CVE-2020-36421
5.3MEDIUMAn issue was discovered in Arm Mbed TLS before 2.23.0. Because of a side channel in modular exponentiation, an RSA private key used in a secure enclave could be disclosed.
Veröffentlicht: 7/19/2021Aktualisiert: 12/3/2025
Beschreibung
An issue was discovered in Arm Mbed TLS before 2.23.0. Because of a side channel in modular exponentiation, an RSA private key used in a secure enclave could be disclosed.
KI-AnalyseKI-gestützt
Betroffene Produkte
armmbed_tls
armmbed_tls
debiandebian_linux
10.0
Referenzen
- https://bugs.gentoo.org/730752Issue TrackingPatchThird Party Advisory
- https://github.com/ARMmbed/mbedtls/issues/3394ExploitIssue TrackingThird Party Advisory
- https://github.com/ARMmbed/mbedtls/releases/tag/v2.16.7Release NotesThird Party Advisory
- https://github.com/ARMmbed/mbedtls/releases/tag/v2.23.0Release NotesThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/12/msg00036.htmlMailing ListThird Party Advisory
- https://bugs.gentoo.org/730752Issue TrackingPatchThird Party Advisory
- https://github.com/ARMmbed/mbedtls/issues/3394ExploitIssue TrackingThird Party Advisory
- https://github.com/ARMmbed/mbedtls/releases/tag/v2.16.7Release NotesThird Party Advisory
- https://github.com/ARMmbed/mbedtls/releases/tag/v2.23.0Release NotesThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/12/msg00036.htmlMailing ListThird Party Advisory