ZeroHour

CVE-2016-10319

CVSS 3.0
5.9 medium
EPSS
2%p74
Published
()
Modified
Description

In ARM Trusted Firmware 1.2 and 1.3, a malformed firmware update SMC can result in copying unexpectedly large data into secure memory because of integer overflows. This affects certain cases involving execution of both AArch64 Generic Trusted Firmware (TF) BL1 code and other firmware update code.

Vendors
arm trusted firmware project
Products
arm trusted firmware
Weakness
CWE-190
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.