CVE-2021-44732: Double Free
Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtlssslsetsession() failure.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-44732.
What is the severity of CVE-2021-44732?
The severity of CVE-2021-44732 is critical, with a severity value of 9.8.
What software is affected by CVE-2021-44732?
ARM mbed TLS versions up to 2.16.12, versions from 2.17.0 to 2.28.0, ARM mbed TLS version 3.0.0, ARM mbed TLS version 3.0.0-preview1, and Debian Debian Linux version 10.0 are affected by CVE-2021-44732.
What is the impact of CVE-2021-44732?
CVE-2021-44732 can lead to a double free vulnerability in certain out-of-memory conditions, which can be exploited by an attacker to potentially execute arbitrary code or cause a denial of service.
How can I fix CVE-2021-44732?
To fix CVE-2021-44732, update to Mbed TLS version 3.0.1 or later, or the patched version provided by your software vendor.