Predictable Seed Vulnerability in Mbed TLS from Arm
CVE-2026-34871
6.7MEDIUM
What is CVE-2026-34871?
An issue has been identified in certain versions of Mbed TLS and TF-PSA-Crypto where the Pseudo-Random Number Generator (PRNG) utilizes a predictable seed. This flaw can potentially allow attackers to predict cryptographic keys generated using the compromised random number generator, posing a significant risk to the integrity and confidentiality of data. Users of the affected versions are urged to review the related security advisories and take appropriate measures to upgrade their systems.