First published: Mon Jan 16 2023(Updated: )
Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects downstream use of get_ext and auth_nvctr. Attackers might be able to trigger dangerous read side effects or obtain sensitive information about microarchitectural state.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ARM Trusted Firmware-A | >=1.2<=2.8 | |
ARM Trusted Firmware-A | >=1.2<=2.8 |
https://trustedfirmware-a.readthedocs.io/en/latest/security_advisories/security-advisory-tfv-10.html
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-47630.
The title of the vulnerability is 'Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certif…'.
The severity of CVE-2022-47630 is high with a CVSS score of 7.4.
CVE-2022-47630 can allow attackers to trigger dangerous read side effects or obtain sensitive information about microarchitectural state through the use of get_ext and auth_nvctr.
Yes, you can find references for CVE-2022-47630 at the following links: [http://www.openwall.com/lists/oss-security/2023/01/16/8](http://www.openwall.com/lists/oss-security/2023/01/16/8), [https://trustedfirmware-a.readthedocs.io/en/latest/security_advisories/security-advisory-tfv-10.html](https://trustedfirmware-a.readthedocs.io/en/latest/security_advisories/security-advisory-tfv-10.html), [https://www.trustedfirmware.org/news/](https://www.trustedfirmware.org/news/).
The CWE ID for CVE-2022-47630 is CWE-125.