PT-2023-15442 · Unknown+1 · Arm Trusted Firmware+1

Demi Marie Obenour

·

Publicado

2023-01-16

·

Atualizado

2026-06-05

·

CVE-2022-47630

CVSS v3.1

7.4

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Trusted Firmware-A versions 2.8 and earlier
Description The issue is related to an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects the downstream use of get ext and auth nvctr. Attackers might be able to trigger dangerous read side effects or obtain sensitive information about microarchitectural state.
Recommendations For versions 2.8 and earlier, consider disabling the X.509 parser for parsing boot certificates until a patch is available. Restrict access to the get ext and auth nvctr functions to minimize the risk of exploitation. Avoid using these functions in sensitive operations until the issue is resolved.

Correção

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-47630
OESA-2023-1899
OPENSUSE-SU-2024:12883-1

Produtos afetados

Debian
Arm Trusted Firmware