PT-2023-15442 · Unknown+1 · Arm Trusted Firmware+1

Demi Marie Obenour

·

Published

2023-01-16

·

Updated

2026-06-05

·

CVE-2022-47630

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Trusted Firmware-A versions 2.8 and earlier
Description The issue is related to an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects the downstream use of get ext and auth nvctr. Attackers might be able to trigger dangerous read side effects or obtain sensitive information about microarchitectural state.
Recommendations For versions 2.8 and earlier, consider disabling the X.509 parser for parsing boot certificates until a patch is available. Restrict access to the get ext and auth nvctr functions to minimize the risk of exploitation. Avoid using these functions in sensitive operations until the issue is resolved.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-47630
OESA-2023-1899
OPENSUSE-SU-2024:12883-1

Affected Products

Debian
Arm Trusted Firmware