Skip to content

Constant time memory compare function

Low
jbech-linaro published GHSA-pjrf-4c8m-w7xp Jun 28, 2021

Package

OP-TEE

Affected versions

< 3.6.0

Patched versions

>= 3.6.0

Description

A constant time memory compare function should be available for the Trusted Applications in the TEE/TA API.

Patches

optee_os.git

  • libutee: TEE_MemCompare(): use constant time algorithm (65551e6)

Workarounds

N/A

References

N/A

OP-TEE ID

OP-TEE-2019-0006

Reported by

Netflix (Bastien Simondi)

For more information

For more information regarding the security incident process in OP-TEE, please read the information that can be found when going to the "Security" page at https://www.trustedfirmware.org.

Severity

Low

CVE ID

No known CVE

Weaknesses

No CWEs