PT-2026-29585 · Arm · Mbed Tls+1

CVE-2026-25835

·

Published

2026-04-01

·

Updated

2026-06-22

CVSS v3.1

7.7

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Mbed TLS versions prior to 3.6.6 TF-PSA-Crypto versions prior to 1.1.0
Description The software uses seeds incorrectly within a Pseudo-Random Number Generator (PRNG). This can lead to predictable random number generation.
Recommendations Update Mbed TLS to version 3.6.6 or later. Update TF-PSA-Crypto to version 1.1.0 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-25835
ECHO-684C-26FC-673D
OPENSUSE-SU-2026:10498-1
OPENSUSE-SU-2026:20875-1
OPENSUSE-SU-2026:21144-1
SUSE-SU-2026:1952-1
SUSE-SU-2026:21440-1
SUSE-SU-2026:21981-1
SUSE-SU-2026:22016-1

Affected Products

Mbed Tls
Tf-Psa-Crypto