An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations. This side channel could be sufficient for a local attacker to recover the plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade mbedtlsUpgrade mbedtls2Upgrade mbedtls3 | Mar 26, 2024 | Jan 31, 2024 |
| Debian | — | Upgrade mbedtls | May 15, 2025 | Jan 31, 2024 |
| Gentoo Linux | — | Upgrade net-libs/mbedtls. | Sep 23, 2024 | Jan 31, 2024 |
| Suse | — | Upgrade libmbedtls14Upgrade libmbedcrypto7-64bitUpgrade libmbedx509-1Upgrade libmbedcrypto7-32bitUpgrade mbedtls-develUpgrade libmbedcrypto7Upgrade libmbedx509-1-64bitUpgrade libmbedtls14-64bitUpgrade libmbedx509-1-32bitUpgrade libmbedtls14-32bit | Feb 1, 2024 | Feb 1, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub