Loading
In Linaro OP-TEE before 3.7.0, by using inconsistent or malformed data, it is possible to call update and final cryptographic functions directly, causing a crash that could leak sensitive information.
Use CWE-327, Linaro vendor hub and Op-Tee product page to widen CVE-2019-25052 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2019-1010292, CVE-2019-1010298 and CVE-2019-1010297 for nearby disclosures in the same product family.