CVE-2026-34877 Details
Description
An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who can modify the serialized structures to induce memory corruption, leading to arbitrary code execution. This is caused by Incorrect Use of Privileged APIs.
A vulnerability exists in Mbed TLS versions 2.19.0 prior to 3.6.5 and in Mbed TLS 4.0.0. The issue arises from inadequate protection of serialized SSL context or session structures, allowing an attacker to modify these structures and induce memory corruption. This could lead to arbitrary code execution. The vulnerability is caused by the incorrect use of privileged APIs.
Users should review their use of TLS session or context serialization and ensure that serialized data is protected against unauthorized access and modification. Recommended measures include storing serialized TLS state only in trusted storage, using cryptographic integrity protection for serialized data, and validating storage integrity before restoring serialized TLS sessions or contexts.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-250 | Execution with Unnecessary Privileges | CISA-ADP |
| CWE-502 | Deserialization of Untrusted Data | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| arm mbed tls | >= 2.19.0, < 3.6.6 |
CPE
Remediation
| |
| trustedfirmware mbed tls | 4.0.0 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 5, 2026 | CPE Deprecation Remap | [email protected] |
| Apr 6, 2026 | Initial Analysis | [email protected] |
| Apr 2, 2026 | CVE Modified | CISA-ADP |
| Apr 2, 2026 | New CVE Received | [email protected] |