First published: Thu Aug 11 2022(Updated: )
TEE_Malloc in Samsung mTower through 0.3.0 allows a trusted application to achieve Excessive Memory Allocation via a large len value, as demonstrated by a Numaker-PFM-M2351 TEE kernel crash.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung mTower | <=0.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-38155 has a high severity rating due to its potential to cause crashes and disrupt trusted applications.
To fix CVE-2022-38155, update the Samsung mTower software to a version beyond 0.3.0 which addresses the excessive memory allocation issue.
CVE-2022-38155 affects the Samsung mTower software version 0.3.0 and earlier.
The root cause of CVE-2022-38155 is excessive memory allocation in the TEE_Malloc function due to large len values.
CVE-2022-38155 can impact system security by allowing a trusted application to crash, potentially leading to a denial of service situation.