CVE-2021-36133: High severity Linaro OP-TEE vulnerability
The OPTEE-OS CSU driver for NXP i.MX SoC devices lacks security access configuration for several models, resulting in TrustZone bypass because the NonSecure World can perform arbitrary memory read/write operations on Secure World memory. This involves a DMA capable peripheral.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-36133?
CVE-2021-36133 is a vulnerability in the OPTEE-OS CSU driver for NXP i.MX SoC devices that allows TrustZone bypass due to the lack of security access configuration.
What is the severity of CVE-2021-36133?
CVE-2021-36133 has a severity rating of 7.1, which is considered high.
Which software is affected by CVE-2021-36133?
The Linaro OP-TEE software is affected by CVE-2021-36133.
How does CVE-2021-36133 work?
CVE-2021-36133 allows the NonSecure World to perform arbitrary memory read/write operations on Secure World memory, potentially bypassing TrustZone.
Is NXP i.MX 6 vulnerable to CVE-2021-36133?
No, NXP i.MX 6 is not vulnerable to CVE-2021-36133.