First published: Tue Dec 07 2021(Updated: )
The OPTEE-OS CSU driver for NXP i.MX SoC devices lacks security access configuration for several models, resulting in TrustZone bypass because the NonSecure World can perform arbitrary memory read/write operations on Secure World memory. This involves a DMA capable peripheral.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linaro OP-TEE | ||
Nxp I.mx 6 | ||
Nxp I.mx 6solox | ||
Nxp I.mx 6ull | ||
Nxp I.mx 6ulz | ||
Nxp I.mx 7ds | ||
Nxp I.mx6sx |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36133 is a vulnerability in the OPTEE-OS CSU driver for NXP i.MX SoC devices that allows TrustZone bypass due to the lack of security access configuration.
CVE-2021-36133 has a severity rating of 7.1, which is considered high.
The Linaro OP-TEE software is affected by CVE-2021-36133.
CVE-2021-36133 allows the NonSecure World to perform arbitrary memory read/write operations on Secure World memory, potentially bypassing TrustZone.
No, NXP i.MX 6 is not vulnerable to CVE-2021-36133.