Skip to main content
EPSS 0.4%top 68%

An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation of the multipart CCM API with an oversized tag_l...

0
Medium
Published: 05/07/2026 (05/07/2026, 01:12:52 UTC)
Source: GCVE Database
Vendor/Project: Microsoft Security Response Center
Product: Microsoft

Description

An out-of-bounds read vulnerability exists in Mbed TLS versions 3.x prior to 3.6.6 in the function mbedtls_ccm_finish(). This flaw allows attackers to read adjacent CCM context data when using the multipart CCM API with an oversized tag length parameter. The vulnerability is identified as CWE-125 (out-of-bounds read). No CVSS score or known exploits in the wild are reported. Affected versions include Mbed TLS 3.0 and related builds. No patch information is provided in the available data.

Affected software

Affected versions
=3.0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/07/2026, 19:44:15 UTC

Technical Analysis

CVE-2026-34876 describes an out-of-bounds read vulnerability in the mbedtls_ccm_finish() function of Mbed TLS 3.x before version 3.6.6. The issue arises when the multipart CCM API is invoked with an oversized tag length, enabling an attacker to read adjacent memory within the CCM context structure. This vulnerability is categorized under CWE-125. The advisory is published by Microsoft Security Response Center, but no explicit patch or remediation details are provided in the source data.

Potential Impact

The vulnerability allows an attacker to read memory adjacent to the CCM context, potentially exposing sensitive cryptographic data or internal state information. There is no indication of active exploitation in the wild. The impact is limited to information disclosure through out-of-bounds memory reads.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or workaround is provided in the available data. Users should monitor Microsoft Security Response Center advisories for updates and apply patches once available.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_vex
Csaf Version
2.0
Publisher
Microsoft Security Response Center
Advisory Id
msrc_CVE-2026-34876
Cve Count
1

Threat ID: 6a998f63acd9273b4919343c

Added to database: 09/03/2026, 15:16:51 UTC

Last enriched: 09/07/2026, 19:44:15 UTC

Last updated: 09/10/2026, 19:36:53 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses