A Buffer Access with Incorrect Length Value vulnerablity in the TEEMACUpdate function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEEMACUpdate with an excessive size value of chunkSize.
A Memory Allocation with Excessive Size Value vulnerablity in the TEERealloc function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEERealloc with an excessive number for the parameter len.
The function teeobjfree in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEEAllocateOperation with a disturbed heap layout, related to uteecrypobjalloc.
A Buffer Access with Incorrect Length Value vulnerablity in the TEECipherUpdate function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEECipherUpdate with an excessive size value of srcLen.
A NULL pointer dereference issue in the TEEMACCompareFinal function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEEMACCompareFinal with a NULL pointer for the parameter operation.
A Buffer Access with Incorrect Length Value vulnerablity in the TEEMACComputeFinal function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEEMACComputeFinal with an excessive size value of messageLen.
There is a NULL pointer dereference in aes256encrypt in Samsung mTower through 0.3.0 due to a missing check on the return value of EVPCIPHERCTXnew.
signpFwInfo in Samsung mTower through 0.3.0 has a missing check on the return value of ECKEYsetprivatekey, leading to a denial of service.
signpFwInfo in Samsung mTower through 0.3.0 has a missing check on the return value of ECKEYsetpublickeyaffinecoordinates, leading to a denial of service.
TEEMalloc in Samsung mTower through 0.3.0 allows a trusted application to achieve Excessive Memory Allocation via a large len value, as demonstrated by a Numaker-PFM-M2351 TEE kernel crash.
Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEEAllocateTransientObject.
Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEEGetObjectInfo1.
The TEEPopulateTransientObject and uteefromattr functions in Samsung mTower 0.3.0 allow a trusted application to trigger a memory overwrite, denial of service, and information disclosure by invoking the function TEEPopulateTransientObject with a large number in the parameter attrCount.