CVE-2024-49195: Trustedfirmware Mbed TLS
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pair
Affected products
- Trustedfirmware Mbed TLS: from 3.5.0, before 3.6.2 (fixed in 3.6.2)
Published 2024-10-15. Last modified 2026-06-17.