CVE Vulnerabilities

CVE-2026-34874

NULL Pointer Dereference

Published: Apr 01, 2026 | Modified: Jun 05, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
Mbed_tlsTrustedfirmware3.5.0 (including)3.6.6 (excluding)
Mbed_tlsTrustedfirmware4.0.0 (including)4.0.0 (including)
MbedtlsUbuntuesm-apps/xenial*

Potential Mitigations

References