CVE-2025-66442 identifies a compiler-induced timing side channel vulnerability affecting RSA and CBC/ECB decryption in Mbed TLS up to version 4.0.0 and TF-PSA-Crypto up to version 1.0.0, specifically when LLVM's select-optimize feature is utilized. With a CVSS score of 5.1 (Medium), this flaw requires local access and high attack complexity, but could result in a high impact on confidentiality by potentially allowing an attacker to extract sensitive cryptographic data. Currently, there is no indication of active exploitation, public exploit code, or significant community attention regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.0.0CPE matchmatch criteria | cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:* | ||
<= 1.0.0CPE matchmatch criteria | cpe:2.3:a:arm:tf-psa-crypto:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.