CVE-2021-32032
HIGHLinaro Trusted Firmware-m < 1.3.0 - Memory Leak
Title source: ruleDescription
In Trusted Firmware-M through 1.3.0, cleaning up the memory allocated for a multi-part cryptographic operation (in the event of a failure) can prevent the abort() operation in the associated cryptographic library from freeing internal resources, causing a memory leak.
References (3)
Scores
CVSS v3
7.5
EPSS
0.0056
EPSS Percentile
68.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-401
Status
published
Affected Products (1)
linaro/trusted_firmware-m
< 1.3.0
Timeline
Published
May 21, 2021
Tracked Since
Feb 18, 2026