CVE-2021-32032: High severity Linaro Trusted Firmware-m vulnerability
In Trusted Firmware-M through 1.3.0, cleaning up the memory allocated for a multi-part cryptographic operation (in the event of a failure) can prevent the abort() operation in the associated cryptographic library from freeing internal resources, causing a memory leak.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-32032?
CVE-2021-32032 is a vulnerability in Trusted Firmware-M through 1.3.0 that can cause a memory leak due to improper memory cleanup in a multi-part cryptographic operation.
How does CVE-2021-32032 impact Linaro Trusted Firmware-M?
CVE-2021-32032 can impact Linaro Trusted Firmware-M versions up to and including 1.3.0.
What is the severity of CVE-2021-32032?
CVE-2021-32032 has a severity rating of 7.5 (High).
How can CVE-2021-32032 be exploited?
CVE-2021-32032 can be exploited by performing a multi-part cryptographic operation that fails, leading to improper memory cleanup.
Is there a fix available for CVE-2021-32032?
Yes, a fix is available for CVE-2021-32032. It is recommended to update to a version of Trusted Firmware-M that is higher than 1.3.0.