CVE-2019-16910: Arm Mbed Crypto

Medium severity, CVSS 5.3. EPSS: 1.8% chance of exploitation in the next 30 days.

Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insufficient entropy for blinding, which might allow an attacker to recover a private key via side-channel attacks if a victim signs the same message many times. (For Mbed TLS, the fix is also available in versions 2.7.12 and 2.16.3.)

Affected products

  • Arm Mbed Crypto: before 2.0.0 (fixed in 2.0.0)
  • Arm Mbed TLS: before 2.7.12 (fixed in 2.7.12); from 2.8.0, before 2.16.3 (fixed in 2.16.3)
  • Debian Debian Linux: version 10.0 only
  • Fedoraproject Fedora: version 29 only; version 30 only; version 31 only
  • Trustedfirmware Mbed TLS: from 2.17.0, before 2.19.0 (fixed in 2.19.0)

Published 2019-09-26. Last modified 2026-06-17.