CVE-2019-1010292: Critical severity Linaro OP-TEE vulnerability
Published Jul 16, 2019
·Updated
Linaro/OP-TEE OP-TEE Prior to version v3.4.0 is affected by: Boundary checks. The impact is: This could lead to corruption of any memory which the TA can access. The component is: opteeos. The fixed version is: v3.4.0.
Affected Software
2 affected components
Linaro OP-TEE<3.4.0
TrustedFirmware OP-TEE<3.4.0
Remediation
Event History
Jul 16, 2019
CVE Published
via MITRE·01:18 PM
Data Sourced
via MITRE·01:18 PM
DescriptionWeakness
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the impact of CVE-2019-1010292?
The impact of CVE-2019-1010292 is the potential corruption of any memory accessible by the Trusted Application (TA).
2
Which component is affected by CVE-2019-1010292?
The optee_os component is affected by CVE-2019-1010292.
3
What is the severity of CVE-2019-1010292?
CVE-2019-1010292 has a severity rating of critical with a value of 9.8.
4
How can I fix CVE-2019-1010292?
The fix for CVE-2019-1010292 is to upgrade to version v3.4.0 of Linaro/OP-TEE OP-TEE.
5
Where can I find more information about CVE-2019-1010292?
You can find more information about CVE-2019-1010292 at the following reference link: [GitHub - OP-TEE optee_os commit](https://github.com/OP-TEE/optee_os/commit/e3adcf566cb278444830e7badfdcc3983e334fd1)