Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-34874

Опубликовано: 01 апр. 2026
Источник: debian
EPSS Низкий

Описание

An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mbedtlsfixed3.6.6-0.1package
mbedtlsno-dsatrixiepackage
mbedtlsno-dsabookwormpackage

Примечания

  • https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-03-null-pointer-dereference-x509/

EPSS

Процентиль: 20%
0.00279
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0.

CVSS3: 7.5
nvd
4 месяца назад

An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0.

msrc
3 месяца назад

An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0.

CVSS3: 7.5
github
4 месяца назад

An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0.

suse-cvrf
2 месяца назад

Security update for ovmf

EPSS

Процентиль: 20%
0.00279
Низкий