Advisory TFMV-14
Title |
OOB flash write in corstone1000 update bricks the secure enclave |
|---|---|
CVE ID |
|
Public Disclosure Date |
Sept 14, 2026 |
Versions Affected |
TF-M v2.3.0 |
Configurations |
Only Corstone-1000 platform |
Impact |
A privileged Corstone-1000 host can permanently brick the Secure Enclave root-of-trust |
Fix Version |
|
Credits |
animo |
Background
The Corstone-1000 FWU bootloader backend writes update payload blocks directly
to flash through ProgramData().
The write address is calculated from the target image partition base plus the number of image bytes already received. Without validating this calculated range against the flash address space and the selected update partition size, a sequence of FWU writes can extend past the end of the intended partition.
Impact
Corruption of Secure Enclave owned flash contents and may cause the root-of-trust boot chain to fail validation on the next reset.
Mitigation
Reject FWU write requests that would exceed the flash address space or the target image partition size before calling the raw flash driver.
SPDX-License-Identifier: BSD-3-Clause
SPDX-FileCopyrightText: Copyright The TrustedFirmware-M Contributors