CVE-2026-58008: Unchecked HKDF key-size input in EL3 causes a stack buffer overflow
Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections.
This issue affects Trusted Firmware: through socfpgav2.14.0.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
Altera Trusted Firmware on HPS is affected through socfpga_v2.14.0. The supplied information does not identify any unaffected release.
What level of access does an attacker need?
The CVSS vector indicates local access, low attack complexity, no user interaction, and high privileges are required. The resulting impact includes high integrity and availability impact, low confidentiality impact, and a scope change.
How can I determine whether a system may be affected?
Identify the Altera Trusted Firmware version deployed on the HPS. Systems running socfpga_v2.14.0 or an earlier affected version should be treated as potentially vulnerable.