The ARM TrustZone Technology on which Trusty is based on contains a vulnerability in access permission settings where the portion of the DRAM reserved for TrustZone is identity-mapped by TLK with read, write, and execute permissions, which gives write access to kernel code and data that is otherwise mapped read only.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://nvidia.custhelp.com/app/answers/detail/a_id/5205 | vendor advisory |