Critical severity9.1NVD Advisory· Published Jul 15, 2022· Updated Jun 17, 2026
CVE-2022-35409
CVE-2022-35409
Description
An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0. In some configurations, an unauthenticated attacker can send an invalid ClientHello message to a DTLS server that causes a heap-based buffer over-read of up to 255 bytes. This can cause a server crash or possibly information disclosure based on error responses. Affected configurations have MBEDTLS_SSL_DTLS_CLIENT_PORT_REUSE enabled and MBEDTLS_SSL_IN_CONTENT_LEN less than a threshold that depends on the configuration: 258 bytes if using mbedtls_ssl_cookie_check, and possibly up to 571 bytes with a custom cookie check function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9- Mbed/Mbed TLSdescription
- osv-coords4 versionspkg:rpm/opensuse/mbedtls-2&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/mbedtls-3&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/mbedtls&distro=openSUSE%20Leap%2015.3pkg:rpm/suse/mbedtls&distro=SUSE%20Package%20Hub%2015%20SP3
< 2.28.1-1.1+ 3 more
- (no CPE)range: < 2.28.1-1.1
- (no CPE)range: < 3.6.6-1.1
- (no CPE)range: < 2.16.9-bp153.2.8.1
- (no CPE)range: < 2.16.9-bp153.2.8.1
Patches
Vulnerability mechanics
References
3- mbed-tls.readthedocs.io/en/latest/security-advisories/advisories/mbedtls-security-advisory-2022-07.htmlnvdExploitMitigationVendor Advisory
- lists.debian.org/debian-lts-announce/2022/12/msg00036.htmlnvdMailing ListThird Party Advisory
- github.com/Mbed-TLS/mbedtls/releasesnvdRelease Notes
News mentions
0No linked articles in our index yet.