CVE-2026-54467: High severity Arm Trusted Firmware-M (TF-M) vulnerability
On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidated, supplied pointer.
Affected Software
Event History
Frequently Asked Questions
Which deployments should be prioritized for review?
Prioritize TF-M deployments on PSOC64 or RP2350 using versions 2 through 2.3.0 that do not include commit 00d1b3e. Other platforms are not identified in the available information.
What access and conditions are required for exploitation?
The vulnerability involves a non-secure supplied pointer during mailbox initialization. The provided vector indicates physical access, low privileges, no user interaction, and high attack complexity are required.
How can I determine whether a build is affected?
Check whether the target is PSOC64 or RP2350, whether it uses TF-M 2 through 2.3.0, and whether commit 00d1b3e is present. A build meeting the platform and version conditions but lacking that commit should be treated as affected.