9.8
CVSSv3

CVE-2021-44732

Published: 20/12/2021 Updated: 24/02/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Mbed TLS prior to 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

arm mbed tls

arm mbed tls 3.0.0

debian debian linux 10.0

Vendor Advisories

Debian Bug report logs - #1002631 mbedtls: CVE-2021-44732: Potential double-free after an out of memory error Package: src:mbedtls; Maintainer for src:mbedtls is James Cowgill <jcowgill@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 26 Dec 2021 08:15:01 UTC Severity: important Tags: sec ...