CVE-2021-44732

CRITICAL

ARM Mbed TLS < 2.16.12 - Double Free

Title source: rule

Description

Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.

Scores

CVSS v3 9.8
EPSS 0.0093
EPSS Percentile 75.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-415
Status published

Affected Products (4)

arm/mbed_tls < 2.16.12
arm/mbed_tls
arm/mbed_tls
debian/debian_linux

Timeline

Published Dec 20, 2021
Tracked Since Feb 18, 2026