An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation of the multipart CCM API with an oversized tag_l...
An out-of-bounds read vulnerability exists in Mbed TLS versions 3.x prior to 3.6.6 in the function mbedtls_ccm_finish(). This flaw allows attackers to read adjacent CCM context data when using the multipart CCM API with an oversized tag length parameter. The vulnerability is identified as CWE-125 (out-of-bounds read). No CVSS score or known exploits in the wild are reported. Affected versions include Mbed TLS 3.0 and related builds. No patch information is provided in the available data.
AI Analysis
Technical Summary
CVE-2026-34876 describes an out-of-bounds read vulnerability in the mbedtls_ccm_finish() function of Mbed TLS 3.x before version 3.6.6. The issue arises when the multipart CCM API is invoked with an oversized tag length, enabling an attacker to read adjacent memory within the CCM context structure. This vulnerability is categorized under CWE-125. The advisory is published by Microsoft Security Response Center, but no explicit patch or remediation details are provided in the source data.
Potential Impact
The vulnerability allows an attacker to read memory adjacent to the CCM context, potentially exposing sensitive cryptographic data or internal state information. There is no indication of active exploitation in the wild. The impact is limited to information disclosure through out-of-bounds memory reads.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or workaround is provided in the available data. Users should monitor Microsoft Security Response Center advisories for updates and apply patches once available.
An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation of the multipart CCM API with an oversized tag_l...
Description
An out-of-bounds read vulnerability exists in Mbed TLS versions 3.x prior to 3.6.6 in the function mbedtls_ccm_finish(). This flaw allows attackers to read adjacent CCM context data when using the multipart CCM API with an oversized tag length parameter. The vulnerability is identified as CWE-125 (out-of-bounds read). No CVSS score or known exploits in the wild are reported. Affected versions include Mbed TLS 3.0 and related builds. No patch information is provided in the available data.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-34876 describes an out-of-bounds read vulnerability in the mbedtls_ccm_finish() function of Mbed TLS 3.x before version 3.6.6. The issue arises when the multipart CCM API is invoked with an oversized tag length, enabling an attacker to read adjacent memory within the CCM context structure. This vulnerability is categorized under CWE-125. The advisory is published by Microsoft Security Response Center, but no explicit patch or remediation details are provided in the source data.
Potential Impact
The vulnerability allows an attacker to read memory adjacent to the CCM context, potentially exposing sensitive cryptographic data or internal state information. There is no indication of active exploitation in the wild. The impact is limited to information disclosure through out-of-bounds memory reads.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or workaround is provided in the available data. Users should monitor Microsoft Security Response Center advisories for updates and apply patches once available.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_vex
- Csaf Version
- 2.0
- Publisher
- Microsoft Security Response Center
- Advisory Id
- msrc_CVE-2026-34876
- Cve Count
- 1
Threat ID: 6a998f63acd9273b4919343c
Added to database: 09/03/2026, 15:16:51 UTC
Last enriched: 09/07/2026, 19:44:15 UTC
Last updated: 09/10/2026, 19:36:53 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.