CVE-2020-36421
5.3MEDIUMAn issue was discovered in Arm Mbed TLS before 2.23.0. Because of a side channel in modular exponentiation, an RSA private key used in a secure enclave could be disclosed.
Published: 7/19/2021Updated: 12/3/2025
Description
An issue was discovered in Arm Mbed TLS before 2.23.0. Because of a side channel in modular exponentiation, an RSA private key used in a secure enclave could be disclosed.
AI AnalysisPowered by AI
Affected Products
armmbed_tls
armmbed_tls
debiandebian_linux
10.0
References
- https://bugs.gentoo.org/730752Issue TrackingPatchThird Party Advisory
- https://github.com/ARMmbed/mbedtls/issues/3394ExploitIssue TrackingThird Party Advisory
- https://github.com/ARMmbed/mbedtls/releases/tag/v2.16.7Release NotesThird Party Advisory
- https://github.com/ARMmbed/mbedtls/releases/tag/v2.23.0Release NotesThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/12/msg00036.htmlMailing ListThird Party Advisory
- https://bugs.gentoo.org/730752Issue TrackingPatchThird Party Advisory
- https://github.com/ARMmbed/mbedtls/issues/3394ExploitIssue TrackingThird Party Advisory
- https://github.com/ARMmbed/mbedtls/releases/tag/v2.16.7Release NotesThird Party Advisory
- https://github.com/ARMmbed/mbedtls/releases/tag/v2.23.0Release NotesThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/12/msg00036.htmlMailing ListThird Party Advisory