漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OP-TEE OS 4.10.0 Use-After-Free via Trusted Application Loader TA_FLAG_CONCURRENT
Vulnerability Description
OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application loader that allows attackers with the ability to load a signed Trusted Application to corrupt secure-world kernel memory by setting the TA_FLAG_CONCURRENT flag in a user TA signed header. Attackers can cause two concurrent sessions to operate on the same shared context without locking, corrupting the uctx->vm_info.regions list during memref parameter mapping and unmapping to free vm_region nodes still in use, resulting in a use-after-free in S-EL1 secure-world kernel memory.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
释放后使用
Vulnerability Title
OP-TEE Trusted OS 竞争条件问题漏洞
Vulnerability Description
OP-TEE Trusted OS是OP-TEE组织的一款可信执行环境操作系统。 OP-TEE Trusted OS 4.10.0及之前版本存在安全漏洞,该漏洞源于Trusted Application loader存在释放后重用问题,攻击者可通过设置TA_FLAG_CONCURRENT标志使并发会话无锁操作同一共享上下文,导致memref参数映射和取消映射过程中释放仍在使用的vm_region节点,破坏安全世界内核内存。
CVSS Information
N/A
Vulnerability Type
N/A