Security Advisory

CVE-2021-44149

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-12-07 20:59:43
Last updated 2024-08-04 04:17:24
Assigner mitre
State PUBLISHED

Description

An issue was discovered in Trusted Firmware OP-TEE Trusted OS through 3.15.0. The OPTEE-OS CSU driver for NXP i.MX6UL SoC devices lacks security access configuration for wakeup-related registers, resulting in TrustZone bypass because the NonSecure World can perform arbitrary memory read/write operations on Secure World memory. This involves a v cycle.