CVE-2022-25334 is a critical stack overflow vulnerability in the Texas Instruments OMAP L138 (secure variants) trusted execution environment (TEE) mask ROM. It allows an attacker to achieve arbitrary code execution in secure supervisor context by exploiting a missing bounds check on the signature size field during module loading. This vulnerability has a CVSS score of 8.8 (HIGH), indicating a local attack vector with low complexity, leading to complete compromise of confidentiality, integrity, and availability of the TEE. While it constitutes a full break of the TEE security architecture, there is currently no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:ti:omap_l138_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.