PT-2026-29820 · Arm · Mbed Tls

0Xiviel

+3

·

Published

2026-04-02

·

Updated

2026-04-07

·

CVE-2026-34877

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mbed TLS versions 2.19.0 through 3.6.5, Mbed TLS version 4.0.0
Description A flaw exists in Mbed TLS that, due to insufficient protection of serialized SSL context or session structures, could allow an attacker who can modify these structures to cause memory corruption, potentially leading to arbitrary code execution. This is a result of Incorrect Use of Privileged APIs.
Recommendations Update to a version beyond 3.6.5. Update to a version beyond 4.0.0.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2026-34877
OPENSUSE-SU-2026:10498-1

Affected Products

Mbed Tls