CVE-2021-44732
CRITICAL
9.8
CVSS Severity Score
Vulnerability Description
Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.
Affected Platforms (CPE)
📦
Arm
Mbed Tls
< 2.16.12📦
Arm
Mbed Tls
>= 2.17.0 and < 2.28.0📦
Trustedfirmware
Mbed Tls
= 3.0.0📦
Trustedfirmware
Mbed Tls
= 3.0.0💻
Debian
