Zeroize tmp buf in mbedtls_mpi_fill_random()
diff --git a/library/bignum.c b/library/bignum.c
index 52edd3d..142aeac 100644
--- a/library/bignum.c
+++ b/library/bignum.c
@@ -1877,6 +1877,8 @@
     MBEDTLS_MPI_CHK( mbedtls_mpi_read_binary( X, buf, size ) );
 
 cleanup:
+    mbedtls_zeroize( buf, sizeof( buf ) );
+
     return( ret );
 }