NULL Pointer Dereference in Mbed TLS Affects Various Versions from Arm
CVE-2026-34874
7.5HIGH
What is CVE-2026-34874?
A vulnerability exists in Mbed TLS versions 3.6.5 and 4.0.0, where a NULL pointer dereference can occur during distinguished name parsing. This flaw permits an attacker to write to address 0, potentially leading to system compromise. It's crucial for users of affected versions to implement updates or patches to secure their systems against this type of attack.