CVE-2021-43619: Buffer Overflow
Published Mar 1, 2022
·Updated
Trusted Firmware M 1.4.x through 1.4.1 has a buffer overflow issue in the Firmware Update partition. In the IPC model, a psafwuwrite caller from SPE or NSPE can overwrite stack memory locations.
Affected Software
4 affected components
Arm Trusted Firmware-m=1.4.0
Arm Trusted Firmware-m=1.4.1
TrustedFirmware Trusted Firmware-m=1.4.0
TrustedFirmware Trusted Firmware-m=1.4.1
Remediation
Patch Available
Event History
Mar 1, 2022
CVE Published
via MITRE·04:31 AM
Data Sourced
via MITRE·04:31 AM
Description
Data Sourced
via NVD·05:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-43619?
CVE-2021-43619 is a buffer overflow issue in the Firmware Update partition of Trusted Firmware M 1.4.x through 1.4.1.
2
How severe is CVE-2021-43619?
CVE-2021-43619 has a severity rating of 7.8 (high).
3
Which software versions are affected by CVE-2021-43619?
Trusted Firmware M versions 1.4.0 and 1.4.1 are affected by CVE-2021-43619.
4
How can a buffer overflow in the Firmware Update partition be exploited?
A caller from SPE or NSPE can overwrite stack memory locations through the psa_fwu_write function in the IPC model.
5
Where can I find more information about CVE-2021-43619?
You can find more information about CVE-2021-43619 at the following references: [link1], [link2], [link3].