← Back

Linaro

linaro

30 CVEs • 5 products

Products (5)

Click to collapse
Toggle
Op Tee
op-tee
Lava
lava
Openamp
openamp
Tf Psa Crypto
tf-psa-crypto

CVEs (30)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Linaro
Trustedfirmware
2Op Tee
Op Tee
Jun 17, 2026
Jul 15, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Code execution in context of TEE core (kernel). The component is: optee_os. The fixed version is: 3.4.0 and later.
2Linaro
Trustedfirmware
2Op Tee
Op Tee
Jun 17, 2026
Jul 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Memory corruption and disclosure of memory content. The component is: optee_os. The fixed version is: 3.4.0 and later.
2Linaro
Trustedfirmware
2Op Tee
Op Tee
Jun 17, 2026
Jul 15, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Rounding error. The impact is: Potentially leaking code and/or data from previous Trusted Application. The component is: optee_os. The fixed version is: 3.4.0 and la...Show more
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Rounding error. The impact is: Potentially leaking code and/or data from previous Trusted Application. The component is: optee_os. The fixed version is: 3.4.0 and later.Show less
2Linaro
Trustedfirmware
2Op Tee
Op Tee
Jun 17, 2026
Jul 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Boundary crossing. The impact is: Memory corruption of the TEE itself. The component is: optee_os. The fixed version is: 3.4.0 and later.
2Debian
Linaro
2Debian Linux
Lava
Nov 21, 2024
Jun 19, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of use of yaml.load() instead of yaml.safe_load() when parsing user data, remote code execution can occur.
2Debian
Linaro
2Debian Linux
Lava
Nov 21, 2024
Jun 19, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can forge an HTTP request that will force lava-server-gunicorn to return any file on the server that is r...Show more
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can forge an HTTP request that will force lava-server-gunicorn to return any file on the server that is readable by lavaserver and valid yaml.Show less
1Linaro
1Lava
Nov 21, 2024
Jun 19, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for file: URLs, a user can force lava-server-gunicorn to download any file from the filesystem if it's readable by lavaserver and valid yaml.
3Libtom
LinaroTrustedfirmware
3Libtomcrypt
Op TeeOp Tee
Jun 5, 2026
Jun 15, 2018
N/A· v4
4.9 MEDIUM· v3
1.9 LOW· v2
LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local mach...Show more
LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.Show less
1Linaro
1Op Tee
Nov 21, 2024
Jan 2, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Linaro's open source TEE solution called OP-TEE, version 2.4.0 (and older) is vulnerable a timing attack in the Montgomery parts of libMPA in OP-TEE resulting in a compromised private RSA key.
1Linaro
1Op Tee
Nov 21, 2024
Jan 2, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Linaro's open source TEE solution called OP-TEE, version 2.4.0 (and older) is vulnerable to the bellcore attack in the LibTomCrypt code resulting in compromised private RSA key.