CVE-2023-31339: Input Validation
Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged attacker to perform out of bound reads, potentially resulting in data leakage and denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-31339?
CVE-2023-31339 is considered to have a medium severity due to potential data leakage and denial of service risks.
How do I fix CVE-2023-31339?
To fix CVE-2023-31339, you should update the ARM Trusted Firmware to a version higher than 2.10.1 or AMD Trusted Firmware-A to above 2023.2.
What types of attacks are possible due to CVE-2023-31339?
CVE-2023-31339 could allow a privileged attacker to perform out of bound reads leading to data exposure or denial of service.
Which devices are affected by CVE-2023-31339?
CVE-2023-31339 affects devices utilizing ARM Trusted Firmware in AMD's Zynq UltraScale+ MPSoC and RFSoC families.
Is there a patch available for CVE-2023-31339?
Yes, patches addressing CVE-2023-31339 are available in the updated versions of the ARM and AMD Trusted Firmware.