CVE-2020-10941: Medium severity libmbedcrypto vulnerability
Arm Mbed TLS before 2.16.5 allows attackers to obtain sensitive information (an RSA private key) by measuring cache usage during an import.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-10941.
How can attackers exploit this vulnerability?
Attackers can exploit this vulnerability by measuring cache usage during an import to obtain sensitive information, such as an RSA private key.
What is the severity rating of CVE-2020-10941?
The severity rating of CVE-2020-10941 is medium, with a CVSS score of 5.9.
Which software versions are affected by this vulnerability?
Arm Mbed Crypto versions up to 3.1.0, ARM mbed TLS versions up to 2.16.5, Fedora 31 and 32, and Debian Linux 10.0 are affected by this vulnerability.
How can I fix this vulnerability?
To fix this vulnerability, it is recommended to update Arm Mbed Crypto to a version higher than 3.1.0 and ARM mbed TLS to a version higher than 2.16.5. For Fedora and Debian Linux, update to the latest available patches and security updates.