Executive brief
Mbed TLS and TF-PSA-Crypto are cryptographic libraries used to secure data and communications, often in embedded devices. A vulnerability was found where the software might use a predictable source of randomness on Linux systems during early boot or installation. This could allow an attacker to predict security keys or bypass encryption, potentially leading to the exposure of sensitive data or unauthorized access to the device.
Technical details
A predictable seed vulnerability exists in Mbed TLS (before 3.6.6 and 4.1.0) and TF-PSA-Crypto (before 1.1.0) due to an insecure fallback mechanism on Linux. When the getrandom() system call is unavailable—due to old kernels (pre-3.17), restricted environments, or toolchain limitations—the library falls back to reading from /dev/urandom. On systems without a hardware RNG or saved entropy files, /dev/urandom can return predictable data during early boot or OS installation. This allows for the generation of predictable cryptographic keys and may leak private keys if randomized ECDSA signatures are used. The fix involves transitioning the fallback from /dev/urandom to /dev/random, which blocks until sufficient entropy is available.
Affected products
- Arm Mbed TLS up to 3.6.5, 4.0.0
- Arm TF-PSA-Crypto up to 1.0.0
Timeline
- 2026-03-31: advisory: Vendor advisory published by Mbed TLS team
- 2026-04-01: disclosed: CVE-2026-34871 published