Navigation: Linux Kernel Driver DataBase - web LKDDB: Main index - O index
The Linux kernel configuration item CONFIG_OPTEE_INSECURE_LOAD_IMAGE
:
CONFIG_OPTEE && CONFIG_ARM64
This loads the BL32 image for OP-TEE as firmware when the driver is probed. This returns -EPROBE_DEFER until the firmware is loadable from the filesystem which is determined by checking the system_state until it is in SYSTEM_RUNNING. This also requires enabling the corresponding option in Trusted Firmware for Arm. The documentation there explains the security threat associated with enabling this as well as mitigations at the firmware and platform level. https://trustedfirmware-a.readthedocs.io/en/latest/threat_model/threat_model.html
Additional documentation on kernel security risks are at Documentation/tee/op-tee.rst.
Raw data from LKDDb:
(none)
This page is automaticly generated with free (libre, open) software lkddb(see lkddb-sources).
The data is retrived from:
Popular queries:
Navigation: Linux Kernel Driver DataBase - web LKDDB: main index - O index
Automatically generated (in year 2025). See also LKDDb sources on GitLab