In Mbed TLS 3.3.0 through 3.5.2 before 3.6.0, a malicious client can cause information disclosure or a denial of service because of a stack buffer over-read (of less than 256 bytes) in a TLS 1.3 server via a TLS 3.1 ClientHello.
Metrics
Affected Vendors & Products
References
History
Fri, 05 Jun 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Trustedfirmware
Trustedfirmware mbed Tls |
|
| CPEs | cpe:2.3:a:trustedfirmware:mbed_tls:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Trustedfirmware
Trustedfirmware mbed Tls |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T01:25:03.067Z
Reserved: 2024-03-24T00:00:00.000Z
Link: CVE-2024-30166
Updated: 2024-08-01T14:13:30.410Z
Status : Analyzed
Published: 2024-04-03T03:15:10.510
Modified: 2026-06-17T07:26:24.430
Link: CVE-2024-30166
No data.
OpenCVE Enrichment
No data.