CVE-2026-25835

Name
CVE-2026-25835
Description
Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG).
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://mbed-tls.readthedocs.io/en/latest/security-advisories/
cve@mitre.org https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-03-rng-cloning/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:* mbed_tls >= 2.18.0 < 3.6.6
cpe:2.3:a:arm:mbed_tls:4.0.0:*:*:*:*:*:*:* mbed_tls == None == 4.0.0
cpe:2.3:a:arm:tf-psa-crypto:*:*:*:*:*:*:*:* tf-psa-crypto >= None < 1.1.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
mbedtls3 edge-community 3.6.6-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
mbedtls3 3.24-community 3.6.6-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
mbedtls edge-main 3.6.6-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
mbedtls 3.23-main 3.6.6-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
mbedtls 3.22-main 3.6.6-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
mbedtls 3.21-main 3.6.6-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
mbedtls 3.20-main 3.6.6-r0 Natanael Copa <ncopa@alpinelinux.org> fixed