NULL pointer dereference in mbed TLS - CVE-2026-34874
Published: April 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper memory management in the function mbedtls_x509_string_to_names() when processing user-supplied distinguished names. A remote attacker can cause a memory allocation failure during the execution of mbedtls_x509_string_to_names() to trigger a null pointer dereference, leading to arbitrary code execution on systems without memory protection at address 0.
On platforms with memory protection, this may result in a segmentation fault or denial of service instead of code execution.
Affected software
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Micro
Server Applications Module
SUSE Package Hub 15
Fedora
mbedtls
qemu-uefi-aarch64
qemu-ovmf-x86_64
qemu-uefi-aarch32
qemu-ovmf-x86_64-debug
ovmf
ovmf-tools
How to mitigate CVE-2026-34874
mbedtls - addressed in versions 3.6.6-1.fc42, 3.6.6-1.fc43, 3.6.6-1.fc44
qemu-uefi-aarch64 - addressed in versions 202408-150700.3.18.1, 202502-160000.5.1
qemu-ovmf-x86_64 - addressed in versions 202408-150700.3.18.1, 202502-160000.5.1
qemu-uefi-aarch32 - update to 202408-150700.3.18.1
qemu-ovmf-x86_64-debug - update to 202408-150700.3.18.1
ovmf - update to 202408-150700.3.18.1
ovmf-tools - update to 202408-150700.3.18.1