CVE-2019-1010294: High severity Linaro OP-TEE vulnerability
Published Jul 15, 2019
·Updated
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Rounding error. The impact is: Potentially leaking code and/or data from previous Trusted Application. The component is: opteeos. The fixed version is: 3.4.0 and later.
Affected Software
2 affected components
Linaro OP-TEE<=3.3.0
TrustedFirmware OP-TEE<=3.3.0
Remediation
Event History
Jul 15, 2019
CVE Published
via MITRE·05:27 PM
Data Sourced
via MITRE·05:27 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2019-1010294.
2
What is the severity level of CVE-2019-1010294?
The severity level of CVE-2019-1010294 is high with a score of 7.5.
3
What is the impact of CVE-2019-1010294?
The impact of CVE-2019-1010294 is the potential leaking of code and/or data from the previous Trusted Application.
4
What is the affected component of CVE-2019-1010294?
The affected component of CVE-2019-1010294 is optee_os.
5
How can I fix CVE-2019-1010294?
You can fix CVE-2019-1010294 by updating to version 3.4.0 or later of Linaro/OP-TEE.