Mbed TLS Vulnerability: Stack Buffer Over-read Affects Information Disclosure or Denial of Service
CVE-2024-30166
9.1CRITICAL
What is CVE-2024-30166?
In Mbed TLS versions 3.3.0 through 3.5.2, a stack buffer over-read vulnerability can be exploited by a malicious client. This issue arises during communication with a TLS 1.3 server via a malformed TLS ClientHello message, potentially leading to information disclosure or a denial of service. Users of affected versions should take immediate steps to upgrade to version 3.6.0 to mitigate this risk.
