vulnerability

Alpine Linux: CVE-2019-18222: Observable Discrepancy

Severity
2
CVSS
(AV:L/AC:M/Au:N/C:P/I:N/A:N)
Published
Jan 23, 2020
Added
Aug 22, 2024
Modified
Dec 5, 2025

Description

The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to recover the private key via side-channel attacks.

Solutions

alpine-linux-upgrade-mbedtlsalpine-linux-upgrade-mbedtls2
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.