CVE-2019-18222: Arm Mbed Crypto
Medium severity, CVSS 4.7. EPSS: 0.3% chance of exploitation in the next 30 days.
The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to recover the private key via side-channel attacks.
Affected products
- Arm Mbed Crypto: before 3.0.0 (fixed in 3.0.0)
- Arm Mbed TLS: before 2.7.13 (fixed in 2.7.13); from 2.8.0, before 2.16.4 (fixed in 2.16.4); from 2.17.0, before 2.20.0 (fixed in 2.20.0)
- Debian Debian Linux: version 10.0 only
- Fedoraproject Fedora: version 30 only; version 31 only
Published 2020-01-23. Last modified 2026-06-17.