The OPTEE-OS CSU driver for NXP i.MX SoC devices lacks security access configuration for several models, resulting in TrustZone bypass because the NonSecure World can perform arbitrary memory read/write operations on Secure World memory. This involves a DMA capable peripheral.
2021-12-07T21:15:08.257
2024-11-21T06:13:11.133
Modified
CVSSv3.1: 7.1 (HIGH)
AV:L/AC:L/Au:N/C:P/I:P/A:N
3.9
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | linaro | op-tee | - | Yes |
Hardware | nxp | i.mx_6 | - | No |
Hardware | nxp | i.mx_6solox | - | No |
Hardware | nxp | i.mx_6ull | - | No |
Hardware | nxp | i.mx_6ulz | - | No |
Hardware | nxp | i.mx_7ds | - | No |
Hardware | nxp | i.mx6sx | - | No |