In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing discrepancy in block cipher padding removal allows an attacker to recover the plaintext when PKCS#7 padding mode is used.
{
"binaries": [
{
"binary_version": "3.6.2-3ubuntu1",
"binary_name": "libmbedcrypto16"
},
{
"binary_version": "3.6.2-3ubuntu1",
"binary_name": "libmbedtls-dev"
},
{
"binary_version": "3.6.2-3ubuntu1",
"binary_name": "libmbedtls21"
},
{
"binary_version": "3.6.2-3ubuntu1",
"binary_name": "libmbedx509-7"
}
]
}