Cryptographic issues in mbed Crypto and mbed TLS - CVE-2019-18222
Published: March 11, 2020 / Updated: July 13, 2026
Vulnerability details
The vulnerability allows an attacker to gain access to sensitive information.
the vulnerability exists due to the ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to recover the private key via side-channel attacks.
Affected software
mbed TLS
Arch Linux
Fedora
mbedtls (Alpine package)
mbedtls
How to mitigate CVE-2019-18222
mbed TLS - addressed in versions 2.7.13, 2.16.4, 2.20.0
mbedtls (Alpine package) - update to 2.16.5-r0
mbedtls - addressed in versions 2.7.13-1.el6, 2.7.13-1.el7, 2.16.4-1.el8, 2.16.4-1.fc30, 2.16.4-1.fc31
External References
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/A3GWQNONS7GRORXZJ7MOJFUEJ2ZJ4OUW/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NGDACU65MYZXXVPQP2EBHUJGOR4RWLVY/
- https://tls.mbed.org/tech-updates/security-advisories
- https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2019-12
- https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2019-12/