PT-2026-29789 · Arm · Mbed Tls

·

CVE-2026-34876

·

Published

2026-04-02

·

Updated

2026-04-07

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mbed TLS versions 3.0 through 3.6.5
Description An out-of-bounds read issue exists in the mbedtls ccm finish() function within the library/ccm.c file of Mbed TLS. This allows attackers to potentially obtain adjacent CCM context data by invoking the multipart CCM API with an oversized tag len parameter. The root cause is the lack of validation of the tag len parameter against the size of the internal 16-byte authentication buffer. The issue impacts the public multipart CCM API in Mbed TLS 3.x, where mbedtls ccm finish() can be directly called by applications.
Recommendations Update to Mbed TLS version 3.6.6 or later.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34876
ECHO-2B14-D1FE-8A7A
OPENSUSE-SU-2026:10498-1

Affected Products

Mbed Tls