VDB
ALPINE-CVE-2026-25835
ALPINE-CVE-2026-25835
PUBLISHED
CVSS 7.699999809265137 HIGH
Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG).
Risk Scores
CVSS v3.1
7.699999809265137
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alpine:v3.23 | mbedtls | 3.6.5-r0, 2.16.2-r0, 2.16.6-r0 |
| Alpine:v3.20 | mbedtls | 2.0.0-r0, 2.11.0-r0, 2.12.0-r0 |
| Alpine:v3.21 | mbedtls | 3.6.5-r0, 2.1.2-r0, 2.12.0-r0 |
| Alpine:v3.22 | mbedtls | 2.4.0-r0, 2.4.1-r0, 2.4.2-r0 |
Timeline
- Apr 1, 2026 CVE Published
- Apr 2, 2026 CVE Updated
- Apr 30, 2026 Distribution Patch