Linaro's open source TEE solution called OP-TEE, version 2.4.0 (and older) is vulnerable to the bellcore attack in the LibTomCrypt code resulting in compromised private RSA key.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.op-tee.org/security-advisories/ | vendor advisory |
https://github.com/OP-TEE/optee_os/blob/2.5.0/CHANGELOG.md | third party advisory |
https://github.com/OP-TEE/optee_os/pull/1610 | third party advisory |