In Arm software implementing the Armv8-M processors (all versions), the stack selection mechanism could be influenced by a stack-underflow attack in v8-M TrustZone based processors. An attacker can cause a change to the stack pointer used by the Secure World from a non-secure application if the stack is not initialized. This vulnerability affects only the software that is based on Armv8-M processors with the Security Extension.
References
Link | Resource |
---|---|
https://developer.arm.com/support/arm-security-updates/armv8-m-stack-sealing | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2020-11-12 11:15
Updated : 2020-12-01 11:37
NVD link : CVE-2020-16273
Mitre link : CVE-2020-16273
JSON object : View
CWE
CWE-191
Integer Underflow (Wrap or Wraparound)
Products Affected
arm
- armv8-m_firmware
- armv8-m