CVE-2026-58004: Crafted oversized firmware image causes EL3 stack overflow during VAB authentication on Trusted Firmware.
Published Sep 24, 2026
·Updated
Out-of-bounds read vulnerability in Altera Trusted Firmware on HPS allows Privilege Escalation and Overflow Buffers.
This issue affects Trusted Firmware: through socfpgav2.14.0.
Affected Software
1 affected component
Altera Trusted Firmware<=socfpga_v2.14.0
Event History
Sep 24, 2026
CVE Published
via MITRE·02:51 PM
Data Sourced
via MITRE·02:51 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability is locally exploitable and requires high privileges. No user interaction is required.
2
Which releases are identified as affected?
Altera Trusted Firmware releases through socfpga_v2.14.0 are identified as affected.