Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.
2021-12-20T08:15:06.620
2024-11-21T06:31:28.383
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | arm | mbed_tls | < 2.16.12 | Yes |
Application | arm | mbed_tls | < 2.28.0 | Yes |
Application | arm | mbed_tls | 3.0.0 | Yes |
Application | arm | mbed_tls | 3.0.0 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |