CVE-2026-34875
Description
A flaw was found in Mbed TLS and TF-PSA-Crypto. This vulnerability, a buffer overflow, occurs during the export of public keys for FFDH (Finite Field Diffie-Hellman) keys. A remote attacker could exploit this to potentially execute arbitrary code, gaining full control over the affected system, or cause a denial of service, making the system unavailable.
Statement
Critical: A buffer overflow flaw in Mbed TLS and TF-PSA-Crypto during FFDH public key export could allow a remote attacker to execute arbitrary code or cause a denial of service. Red Hat products utilizing Mbed TLS for FFDH key operations are susceptible if they expose this functionality to untrusted input.
Mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Understanding the Weakness (CWE)
Integrity,Confidentiality,Availability
Technical Impact: Modify Memory; Execute Unauthorized Code or Commands
Buffer overflows often can be used to execute arbitrary code, which is usually outside the scope of the product's implicit security policy. This can often be used to subvert any other security service.
Availability
Technical Impact: Modify Memory; DoS: Crash, Exit, or Restart; DoS: Resource Consumption (CPU)
Buffer overflows generally lead to crashes. Other attacks leading to lack of availability are possible, including putting the product into an infinite loop.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.