Mbed-TLS.mbedtls is vulnerable to Covert Timing Channel
30
Low Risk
Mbed TLS and TF-PSA-Crypto may be vulnerable to timing side-channel attacks when built with affected Clang compiler optimizations that break constant-time padding validation. An attacker capable of submitting chosen ciphertexts and performing precise timing measurements may exploit these differences to mount a padding oracle attack and recover decrypted plaintext, although private keys are not exposed.
You are affected if you are using a version that falls within the vulnerable range.
Mbed-TLS.mbedtls is vulnerable to Covert Timing Channel in all versions.
Affected users should rebuild Mbed-TLS.mbedtls with the LLVM option select-optimize disabled, for example by using only default optimization flags such as -O2 or -Os.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant