Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtlssslset_session() failure.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "2.16.12"
},
{
"introduced": "2.17.0"
},
{
"fixed": "2.28.0"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.0-NA"
}
]
}