First published: Fri May 21 2021(Updated: )
In Trusted Firmware-M through 1.3.0, cleaning up the memory allocated for a multi-part cryptographic operation (in the event of a failure) can prevent the abort() operation in the associated cryptographic library from freeing internal resources, causing a memory leak.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linaro Trusted Firmware-m | <=1.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-32032 is a vulnerability in Trusted Firmware-M through 1.3.0 that can cause a memory leak due to improper memory cleanup in a multi-part cryptographic operation.
CVE-2021-32032 can impact Linaro Trusted Firmware-M versions up to and including 1.3.0.
CVE-2021-32032 has a severity rating of 7.5 (High).
CVE-2021-32032 can be exploited by performing a multi-part cryptographic operation that fails, leading to improper memory cleanup.
Yes, a fix is available for CVE-2021-32032. It is recommended to update to a version of Trusted Firmware-M that is higher than 1.3.0.