PT-2026-29585 · Arm · Tf-Psa-Crypto+1

Published

2026-04-01

·

Updated

2026-04-07

·

CVE-2026-25835

CVSS v3.1

7.7

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Mbed TLS versions prior to 3.6.6 TF-PSA-Crypto versions prior to 1.1.0
Description The software uses seeds incorrectly within a Pseudo-Random Number Generator (PRNG). This can lead to predictable random number generation.
Recommendations Update Mbed TLS to version 3.6.6 or later. Update TF-PSA-Crypto to version 1.1.0 or later.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-25835
OPENSUSE-SU-2026:10498-1

Affected Products

Mbed Tls
Tf-Psa-Crypto