Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-34875

Опубликовано: 01 апр. 2026
Источник: redhat
CVSS3: 9.8
EPSS Низкий

Описание

An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.

A flaw was found in Mbed TLS and TF-PSA-Crypto. This vulnerability, a buffer overflow, occurs during the export of public keys for FFDH (Finite Field Diffie-Hellman) keys. A remote attacker could exploit this to potentially execute arbitrary code, gaining full control over the affected system, or cause a denial of service, making the system unavailable.

Отчет

Critical: A buffer overflow flaw in Mbed TLS and TF-PSA-Crypto during FFDH public key export could allow a remote attacker to execute arbitrary code or cause a denial of service. Red Hat products utilizing Mbed TLS for FFDH key operations are susceptible if they expose this functionality to untrusted input.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Дополнительная информация

Статус:

Critical
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2453963mbedtls: Mbed TLS and TF-PSA-Crypto: Arbitrary code execution due to buffer overflow in FFDH key export

EPSS

Процентиль: 29%
0.00366
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
4 месяца назад

An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.

CVSS3: 9.8
nvd
4 месяца назад

An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.

msrc
3 месяца назад

An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.

CVSS3: 9.8
debian
4 месяца назад

An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1. ...

CVSS3: 9.8
github
4 месяца назад

An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.

EPSS

Процентиль: 29%
0.00366
Низкий

9.8 Critical

CVSS3