DEBIAN-CVE-2022-46392

Source
https://security-tracker.debian.org/tracker/CVE-2022-46392
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-46392.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2022-46392
Upstream
Published
2022-12-15T23:15:10.513Z
Modified
2025-11-14T04:05:26.971622Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough information about memory accesses (typically, an untrusted operating system attacking a secure enclave) can recover an RSA private key after observing the victim performing a single private-key operation, if the window size (MBEDTLSMPIWINDOW_SIZE) used for the exponentiation is 3 or smaller.

References

Affected packages

Debian:11 / mbedtls

Package

Name
mbedtls
Purl
pkg:deb/debian/mbedtls?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.16.9-0.1+deb11u1

Affected versions

2.*

2.16.9-0.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / mbedtls

Package

Name
mbedtls
Purl
pkg:deb/debian/mbedtls?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.28.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / mbedtls

Package

Name
mbedtls
Purl
pkg:deb/debian/mbedtls?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.28.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14 / mbedtls

Package

Name
mbedtls
Purl
pkg:deb/debian/mbedtls?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.28.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}