mirror of
https://github.com/Mbed-TLS/mbedtls.git
synced 2026-09-03 08:49:58 +00:00
Merge pull request #1424 from gilles-peskine-arm/pkcs7-padding-error-timing-leak-cveid-3.6
CVE ID for PKCS7 padding timing leak in psa_cipher_finish
This commit is contained in:
@@ -2,4 +2,4 @@ Security
|
||||
* Fix a timing side channel in CBC-PKCS7 decryption that could
|
||||
allow an attacker who can submit chosen ciphertexts to recover
|
||||
some plaintexts through a timing-based padding oracle attack.
|
||||
Credits to Beat Heeb from Oberon microsystems AG. CVE-TODO
|
||||
Credits to Beat Heeb from Oberon microsystems AG. CVE-2025-59438
|
||||
|
||||
Reference in New Issue
Block a user