An issue was discovered in Arm Mbed TLS before 2.23.0. A side channel allows recovery of an ECC private key, related to mbedtlsecpcheckpubpriv, mbedtlspkparsekey, mbedtlspkparsekeyfile, mbedtlsecpmul, and mbedtlsecpmul_restartable.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "2.16.7"
},
{
"introduced": "2.17.0"
},
{
"fixed": "2.23.0"
}
]
}