In ARM Trusted Firmware 1.2 and 1.3, a malformed firmware update SMC can result in copying unexpectedly large data into secure memory because of integer overflows. This affects certain cases involving execution of both AArch64 Generic Trusted Firmware (TF) BL1 code and other firmware update code.
References
Link | Resource |
---|---|
https://github.com/ARM-software/arm-trusted-firmware/wiki/ARM-Trusted-Firmware-Security-Advisory-TFV-1 | Issue Tracking Patch VDB Entry |
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-04-06 08:59
Updated : 2017-04-12 12:16
NVD link : CVE-2016-10319
Mitre link : CVE-2016-10319
JSON object : View
CWE
CWE-190
Integer Overflow or Wraparound
Products Affected
arm_trusted_firmware_project
- arm_trusted_firmware