Security Advisories
ID |
Title |
|---|---|
NS world may cause the CPU to perform an unexpected return operation due to unsealed stacks. |
|
Invoking Secure functions from handler mode may cause TF-M IPC model to behave unexpectedly. |
|
|
|
NSPE may access secure keys stored in TF-M Crypto service in Profile Small with Crypto key ID encoding disabled. |
|
|
|
Partial tag comparison when using Chacha20-Poly1305 on the PSA driver API interface in CryptoCell enabled platforms |
|
ARoT can access PRoT data via debug logging functionality |
|
Unchecked user-supplied pointer via mailbox messages may cause write of arbitrary address |
|
FWU does not check the length of the TLV’s payload |
|
Missing NS pointer validation in platform mailbox init |
|
Incorrect FMP Header Fragment Reconstruction Allows Attacker-Controlled Firmware Version Values |
|
Pre-auth OOB write in RSE SFCP handshake hijacks BL1 boot-ROM control flow |
|
Plaintext SFCP packet on RSE returns delegated-attestation private key |
|
OOB flash write in corstone1000 update bricks the secure enclave |
SPDX-License-Identifier: BSD-3-Clause
SPDX-FileCopyrightText: Copyright The TrustedFirmware-M Contributors