mbedtls is vulnerable to information disclosure. A Lucky 13 timing side channel in mbedtls_ssl_decrypt_buf
in library/ssl_msg.c
allows an attacker to recover secret key information.
lists.debian.org/debian-lts-announce/2022/12/msg00036.html
lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5OSOFUD6UTGTDDSQRS62BPXDU52I6PUA/
lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IRPBHCQKZXHVKOP5O5EWE7P76AWGUXQJ/
lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OD3NM6GD73CTFFRBKG5G2ACXGG7QQHCC/
lists.fedoraproject.org/archives/list/[email protected]/message/5OSOFUD6UTGTDDSQRS62BPXDU52I6PUA/
lists.fedoraproject.org/archives/list/[email protected]/message/IRPBHCQKZXHVKOP5O5EWE7P76AWGUXQJ/
lists.fedoraproject.org/archives/list/[email protected]/message/OD3NM6GD73CTFFRBKG5G2ACXGG7QQHCC/
tls.mbed.org/tech-updates/security-advisories
tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2020-09-1