CVE-2024-30166

Severity CVSS v4.0:
Pending analysis
Type:
CWE-121 Stack-based Buffer Overflow
Publication date:
03/04/2024
Last modified:
27/06/2025

Description

In Mbed TLS 3.3.0 through 3.5.2 before 3.6.0, a malicious client can cause information disclosure or a denial of service because of a stack buffer over-read (of less than 256 bytes) in a TLS 1.3 server via a TLS 3.1 ClientHello.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:* 3.3.0 (including) 3.6.0 (excluding)