CVE-2020-36476: Arm Mbed TLS

High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.

An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS). There is missing zeroization of plaintext buffers in mbedtls_ssl_read to erase unused application data from memory.

Affected products

  • Arm Mbed TLS: before 2.7.17 (fixed in 2.7.17); from 2.8.0, before 2.16.8 (fixed in 2.16.8); from 2.17.0, before 2.24.0 (fixed in 2.24.0)
  • Debian Debian Linux: version 9.0 only; version 10.0 only

Published 2021-08-23. Last modified 2026-06-17.