An unvalidated input in Silicon Labs TrustZone implementation in v4.3.x and earlier of the Gecko SDK allows an attacker to access the trusted region of memory from the untrusted region.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://github.com/SiliconLabs/gecko_sdk | product |
https://community.silabs.com/069Vm0000004NinIAE | permissions required |