CVE-2021-44732

Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.

critical 9.8 CVSS 3.1
Published: Dec 20, 2021
Modified: Jun 5, 2026
Vendor: Arm
Product: Mbed Tls
Versions: 3.0.0,10.0

Description

Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.

References

Related CVEs