CVE-2026-13465: EL3 Stack Buffer Overflow in FCS HKDF Request
Published Sep 24, 2026
·Updated
Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections.
This issue affects Trusted Firmware: through socfpgav2.14.0.
Affected Software
1 affected component
Altera Trusted Firmware<=socfpga_v2.14.0
Event History
Sep 24, 2026
CVE Published
via MITRE·02:51 PM
Data Sourced
via MITRE·02:51 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is realistically exposed to exploitation?
Systems running Altera Trusted Firmware through socfpga_v2.14.0 are affected. The CVSS vector indicates the attack requires local access and high privileges.
2
Does exploitation require user interaction or network access?
No user interaction is required. The listed attack vector is local, so the issue is not described as remotely exploitable over the network.
3
What security impact can successful exploitation have?
The vulnerability is rated high severity with a CVSS score of 8.1. The vector indicates low confidentiality impact and high integrity and availability impact, with scope changed.