New issue
Advanced search Search tips

Issue 640807 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Sep 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: libtomcrypt/OP-TEE Bleichenbacher Attack

Project Member Reported by mtjz@google.com, Aug 24 2016

Issue description

VULNERABILITY DETAILS
CERT has contacted Google about a vulnerability in libtomcrypt/OP-TEE.  This is a Bleichenbacher signature forgery vulnerability in the rsa_verify_hash_ex function in libtomcrypt, which is embedded in OP-TEE.

My search of the internal ChromeOS code tree has found some OP-TEE-related code, but it's not clear to me whether CrOS is vulnerable or not.

See internal Google bug #31065292 for more information.

VERSION
Chrome Version: ????
Operating System: ChromeOS only
 
Labels: OS-Chrome
Cc: awhalley@chromium.org
Owner: rickyz@chromium.org
Status: Assigned (was: Unconfirmed)
Ricky, can you please take a look.

Comment 4 by rickyz@chromium.org, Aug 25 2016

Hi, can you please describe where in Chrome OS you saw references to OP-TEE? I did not think we used trustzone anywhere on Chrome OS.

Comment 5 by mtjz@google.com, Aug 25 2016

Code Search uncovered some traces of it in http://cs/chromeos_internal/src/partner_private/rockchip-kernel/security/optee_linuxdriver/README.md?l=1, but that's not a terribly strong indication that it's actually used.
Project Member

Comment 6 by sheriffbot@chromium.org, Aug 25 2016

Labels: Hotlist-Google

Comment 7 by vakh@chromium.org, Sep 2 2016

rickyz@ -- any update on this? thanks.

Comment 8 by rickyz@chromium.org, Sep 19 2016

Status: WontFix (was: Assigned)
I looked around, and do not believe Chrome OS uses trustzone anywhere, so we should not be affected.
Project Member

Comment 9 by sheriffbot@chromium.org, Dec 27 2016

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment