First published: Tue Mar 01 2022(Updated: )
Trusted Firmware M 1.4.x through 1.4.1 has a buffer overflow issue in the Firmware Update partition. In the IPC model, a psa_fwu_write caller from SPE or NSPE can overwrite stack memory locations.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Arm Trusted Firmware-m | =1.4.0 | |
Arm Trusted Firmware-m | =1.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-43619 is a buffer overflow issue in the Firmware Update partition of Trusted Firmware M 1.4.x through 1.4.1.
CVE-2021-43619 has a severity rating of 7.8 (high).
Trusted Firmware M versions 1.4.0 and 1.4.1 are affected by CVE-2021-43619.
A caller from SPE or NSPE can overwrite stack memory locations through the psa_fwu_write function in the IPC model.
You can find more information about CVE-2021-43619 at the following references: [link1], [link2], [link3].