PT-2024-15359 · Arm · Arm Cortex-M Security Extensions
Published
2024-04-24
·
Updated
2024-08-09
·
CVE-2024-0151
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Software using Cortex-M Security Extensions (CMSE) compiled using toolchains that implement 'Arm v8-M Security Extensions Requirements on Development Tools' prior to version 1.4
Description
The issue is related to insufficient argument checking in Secure state Entry functions. This allows an attacker to pass values to Secure state that are out of range for types smaller than 32-bits, potentially leading to incorrect operations in secure state.
Recommendations
For software using Cortex-M Security Extensions (CMSE) compiled using toolchains that implement 'Arm v8-M Security Extensions Requirements on Development Tools' prior to version 1.4, consider updating the toolchain to version 1.4 or later to address the issue.
At the moment, there is no information about additional mitigation measures.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arm Cortex-M Security Extensions