CVE-2026-7328: Unverified AXI Address in Subsystem Mode Commands Enables Denial of Service
Missing authorization in Caliptra Core Runtime Firmware (INVOKEDPEMLDSA87, CMAESGCMDECRYPTDMA, EXTERNALMAILBOXCMD commands) in subsystem mode allows a privileged local attacker to cause a denial of service via mailbox commands containing unverified AXI addresses. The security impact beyond availability is integration-specific.
This issue affects Core Runtime Firmware: 2.1.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7328?
CVE-2026-7328 has a medium severity rating of 6.8 according to the CVSS score.
How do I fix CVE-2026-7328?
To address CVE-2026-7328, ensure that the Caliptra Core Runtime Firmware is updated to the latest version that includes the necessary security patches.
What type of attack does CVE-2026-7328 facilitate?
CVE-2026-7328 enables a privileged local attacker to perform a denial of service attack by sending mailbox commands with unverified AXI addresses.
Which commands are affected by CVE-2026-7328?
The affected commands in CVE-2026-7328 are INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, and EXTERNAL_MAILBOX_CMD.
What is the potential impact of CVE-2026-7328?
The potential impact of CVE-2026-7328 is a denial of service condition, which can disrupt the normal functioning of the system.