Critical severity9.1NVD Advisory· Published Apr 3, 2024· Updated Jun 17, 2026
CVE-2024-30166
CVE-2024-30166
Description
In Mbed TLS 3.3.0 through 3.5.2 before 3.6.0, a malicious client can cause information disclosure or a denial of service because of a stack buffer over-read (of less than 256 bytes) in a TLS 1.3 server via a TLS 3.1 ClientHello.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Mbed TLS/Mbed TLSdescription
Patches
Vulnerability mechanics
References
2- mbed-tls.readthedocs.io/en/latest/tech-updates/security-advisories/nvdVendor Advisory
- github.com/Mbed-TLS/mbedtls/releases/tag/v3.6.0nvdRelease Notes
News mentions
0No linked articles in our index yet.