In ARM Trusted Firmware 1.2 and 1.3, a malformed firmware update SMC can result in copying unexpectedly large data into secure memory because of integer overflows. This affects certain cases involving execution of both AArch64 Generic Trusted Firmware (TF) BL1 code and other firmware update code.
References
Link | Resource |
---|---|
https://github.com/ARM-software/arm-trusted-firmware/wiki/ARM-Trusted-Firmware-Security-Advisory-TFV-1 | Issue Tracking Patch VDB Entry |
https://github.com/ARM-software/arm-trusted-firmware/wiki/ARM-Trusted-Firmware-Security-Advisory-TFV-1 | Issue Tracking Patch VDB Entry |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 02:43
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/ARM-software/arm-trusted-firmware/wiki/ARM-Trusted-Firmware-Security-Advisory-TFV-1 - Issue Tracking, Patch, VDB Entry |
Information
Published : 2017-04-06 15:59
Updated : 2024-11-21 02:43
NVD link : CVE-2016-10319
Mitre link : CVE-2016-10319
CVE.ORG link : CVE-2016-10319
JSON object : View
Products Affected
arm_trusted_firmware_project
- arm_trusted_firmware
CWE
CWE-190
Integer Overflow or Wraparound