Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Linaro

First CVE: Jan 2, 2018Active for: 9 yearsTotal CVEs: 9

Linaro develops a narrowly scoped portfolio centered on trusted execution environment components and test infrastructure—notably OP-TEE, Trusted Firmware-M, and LAVA—that serve as foundational elements in ARM-based embedded and mobile systems. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and they recur through weakness classes including improper input validation, sensitive information exposure, and code-injection vectors that are characteristic of security-sensitive firmware and test frameworks. Defenders should monitor this vendor's advisories closely given the privileged role of these components in the system boot and trust chain; current severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Linaro over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 2, 2018
8 years ago
Most Recent CVE
May 1, 2026
85 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-37540CRITICAL
OpenAMP v2025.10.0 ELF loader contains an integer overflow vulnerability in firmware image parsing. In elf_loader.c, it performs multiplication of two attacker-controlled 16-bit va
May 1, 20269.837NONO
CVE-2022-45132CRITICAL
In Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be achieved through user-submitted Jinja2 template. The REST API endpoint for validat
Nov 18, 20229.832NONO
CVE-2018-12565HIGH
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of use of yaml.load() instead of yaml.safe_load() when parsing user data, remote code execution can occur.
Jun 19, 20188.827NONO
CVE-2017-1000412HIGH
Linaro's open source TEE solution called OP-TEE, version 2.4.0 (and older) is vulnerable to the bellcore attack in the LibTomCrypt code resulting in compromised private RSA key.
Jan 2, 20187.525NONO
CVE-2022-44641MEDIUM
In Linaro Automated Validation Architecture (LAVA) before 2022.11, users with valid credentials can submit crafted XMLRPC requests that cause a recursive XML entity expansion, lead
Nov 18, 20226.523NONO
CVE-2022-42902HIGH
In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavatable.py. Due to improper input sanitization, an anonymous use
Oct 13, 20228.822NONO
CVE-2017-1000413MEDIUM
Linaro's open source TEE solution called OP-TEE, version 2.4.0 (and older) is vulnerable a timing attack in the Montgomery parts of libMPA in OP-TEE resulting in a compromised priv
Jan 2, 20185.922NONO
CVE-2018-12564MEDIUM
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can forge an HTTP request that will force lava-server-gunicorn to
Jun 19, 20186.521NONO
CVE-2018-12563MEDIUM
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for file: URLs, a user can force lava-server-gunicorn to download any file from the filesystem if it'
Jun 19, 20186.517NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
44%
33%
22%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (88.9%)
High1 (11.1%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low5 (55.6%)
High0 (0.0%)
None4 (44.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Linaro.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Linaro — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Linaro's Products

View all 1 CNAs →

Top CWEs