An issue was discovered in Arm Mbed TLS before 2.23.0. A remote attacker can recover plaintext because a certain Lucky 13 countermeasure doesn't properly consider the case of a hardware accelerator.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "2.16.7"
},
{
"introduced": "2.17.0"
},
{
"fixed": "2.23.0"
}
]
}