CVE-2016-10319

In ARM Trusted Firmware 1.2 and 1.3, a malformed firmware update SMC can result in copying unexpectedly large data into secure memory because of integer overflows. This affects certain cases involving execution of both AArch64 Generic Trusted Firmware (TF) BL1 code and other firmware update code.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:arm_trusted_firmware_project:arm_trusted_firmware:1.2:*:*:*:*:*:*:*
cpe:2.3:o:arm_trusted_firmware_project:arm_trusted_firmware:1.3:*:*:*:*:*:*:*

History

21 Nov 2024, 02:43

Type Values Removed Values Added
References () https://github.com/ARM-software/arm-trusted-firmware/wiki/ARM-Trusted-Firmware-Security-Advisory-TFV-1 - Issue Tracking, Patch, VDB Entry () https://github.com/ARM-software/arm-trusted-firmware/wiki/ARM-Trusted-Firmware-Security-Advisory-TFV-1 - Issue Tracking, Patch, VDB Entry

Information

Published : 2017-04-06 15:59

Updated : 2024-11-21 02:43


NVD link : CVE-2016-10319

Mitre link : CVE-2016-10319

CVE.ORG link : CVE-2016-10319


JSON object : View

Products Affected

arm_trusted_firmware_project

  • arm_trusted_firmware
CWE
CWE-190

Integer Overflow or Wraparound