CVE-2026-11835: Caliptra Update-Reset Secure-Boot Bypass via Attacker-Chosen AXI Staging Address (TOCTOU)
Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateResetFlow::run()) in subsystem mode allows a compromised local attacker to silently bypass secure boot by supplying an AXI staging address that is not validated against the strap-configured SSEXTERNALSTAGINGAREABASEADDR, enabling firmware to be modified between verification and loading into ICCM. Attestation continues to report the originally verified image digest, masking the compromise. Exploitation requires a compromised MCU firmware with AXI manager access to unprotected SRAM reachable by Caliptra.
This issue affects Core ROM: 2.1.0 through 2.1.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11835?
CVE-2026-11835 has a medium severity score of 5.6.
How do I fix CVE-2026-11835?
To fix CVE-2026-11835, ensure that input validation is properly implemented for AXI staging addresses in the Caliptra Core ROM.
What type of vulnerability is CVE-2026-11835?
CVE-2026-11835 is a Time-of-Check Time-of-Use (TOCTOU) vulnerability related to missing input validation.
Who is affected by CVE-2026-11835?
Local attackers with access to the system could exploit CVE-2026-11835 to bypass secure boot mechanisms.
What software does CVE-2026-11835 affect?
CVE-2026-11835 affects Caliptra Core ROM used in the Caliptra system.