Overview
What is CVE-2025-66442?
In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected.
Vulnerability intelligence
CVE-2025-66442 and is rated Medium severity with a CVSS score of 5.1. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected.