CVE-2021-44732 is a critical double free vulnerability in Mbed TLS versions prior to 3.0.1, specifically impacting arm and Debian Linux distributions utilizing Mbed TLS. This flaw, rated 9.8 CRITICAL, can be exploited remotely without user interaction, potentially leading to complete compromise of confidentiality, integrity, and availability. Despite its high severity, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.16.12CPE matchmatch criteria | cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:* | ||
>= 2.17.0, < 2.28.0CPE matchmatch criteria | cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:* | ||
3.0.0CPE matchmatch criteria | cpe:2.3:a:trustedfirmware:mbed_tls:3.0.0:-:*:*:*:*:*:* | ||
3.0.0CPE matchmatch criteria | cpe:2.3:a:trustedfirmware:mbed_tls:3.0.0:preview1:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Mbed TLS vulnerabilities
Mar 25, 2026USN-8123-1: Mbed TLS vulnerabilities
Mar 25, 2026USN-8123-1: Mbed TLS vulnerabilities
Mar 25, 2026Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.
Dec 14, 2021