VDB

GCVE-VVD-MAGEIA-2020-53

GCVE-VVD-MAGEIA-2020-53
Advisory Published
Vulnetix · Advisory published February 18, 2020
This update from mbedTLS 2.16.2 to mbedTLS 2.16.4 fixes several security vulnerabilities, among which: The deterministic ECDSA calculation reused the scheme's HMAC-DRBG to implement blinding. Because of this for the same key and message the same blinding value was generated. This reduced the effectiveness of the countermeasure and leaked information about the private key through side channels (CVE-2019-16910). Fix side channel vulnerability in ECDSA. Our bignum implementation is not constant time/constant trace, so side channel attacks can retrieve the blinded value, factor it (as it is smaller than RSA keys and not guaranteed to have only large prime factors), and then, by brute force, recover the key (CVE-2019-18222). See release notes for details.

Affected Products

VendorProductVersionsPlatforms
Mageianvidia3400 (affected), 340.108-2.mga7.nonfree (unaffected)
Mageiambedtls0 (affected), 2.16.4-1.mga7 (unaffected), 0 (affected), 2.16.4-1.mga7 (unaffected)

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›