CVE-2019-25052

In Linaro OP-TEE before 3.7.0, by using inconsistent or malformed data, it is possible to call update and final cryptographic functions directly, causing a crash that could leak sensitive information.

critical 9.1 CVSS 3.1
Published: Aug 11, 2021
Modified: Jun 5, 2026
Vendor: Trustedfirmware
Product: Op-Tee

Description

In Linaro OP-TEE before 3.7.0, by using inconsistent or malformed data, it is possible to call update and final cryptographic functions directly, causing a crash that could leak sensitive information.

References

Related CVEs