漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OP-TEE OS 4.10.0 NULL Pointer Dereference DoS via Widevine PTA open_session
Vulnerability Description
OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a null pointer dereference vulnerability in the Widevine pseudo-TA open_session handler that allows Normal World clients to cause a denial of service when CFG_WIDEVINE_PTA is enabled. Attackers can open a session directly on the Widevine PTA to trigger an unconditional dereference of a NULL calling session pointer via is_user_ta_ctx(), faulting the TEE at S-EL1 and crashing the trusted execution environment.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
空指针解引用
Vulnerability Title
OP-TEE Trusted OS 异常处理不当漏洞
Vulnerability Description
OP-TEE Trusted OS是OP-TEE组织的一款可信执行环境操作系统。 OP-TEE Trusted OS 4.10.0及之前版本存在异常处理不当漏洞,该漏洞源于Widevine伪TA的open_session处理器存在空指针取消引用问题,可能导致启用CFG_WIDEVINE_PTA时普通世界客户端引发拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A