Trusted Firmware M Arm Trusted Firmware M

Do you want an email whenever new security vulnerabilities are reported in Arm Trusted Firmware M?

By the Year

In 2024 there have been 0 vulnerabilities in Arm Trusted Firmware M . Last year Trusted Firmware M had 1 security vulnerability published. Right now, Trusted Firmware M is on track to have less security vulnerabilities in 2024 than it did last year.

Year Vulnerabilities Average Score
2024 0 0.00
2023 1 7.50
2022 1 7.80
2021 0 0.00
2020 0 0.00
2019 0 0.00
2018 0 0.00

It may take a day or so for new Trusted Firmware M vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Arm Trusted Firmware M Security Vulnerabilities

In Trusted Firmware-M through TF-Mv1.8.0, for platforms

CVE-2023-40271 7.5 - High - September 08, 2023

In Trusted Firmware-M through TF-Mv1.8.0, for platforms that integrate the CryptoCell accelerator, when the CryptoCell PSA Driver software Interface is selected, and the Authenticated Encryption with Associated Data Chacha20-Poly1305 algorithm is used, with the single-part verification function (defined during the build-time configuration phase) implemented with a dedicated function (i.e., not relying on usage of multipart functions), the buffer comparison during the verification of the authentication tag does not happen on the full 16 bytes but just on the first 4 bytes, thus leading to the possibility that unauthenticated payloads might be identified as authentic. This affects TF-Mv1.6.0, TF-Mv1.6.1, TF-Mv1.7.0, and TF-Mv1.8.

Incorrect Comparison

Trusted Firmware M 1.4.x through 1.4.1 has a buffer overflow issue in the Firmware Update partition

CVE-2021-43619 7.8 - High - March 01, 2022

Trusted Firmware M 1.4.x through 1.4.1 has a buffer overflow issue in the Firmware Update partition. In the IPC model, a psa_fwu_write caller from SPE or NSPE can overwrite stack memory locations.

Classic Buffer Overflow

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Arm Trusted Firmware M or by Arm? Click the Watch button to subscribe.

Arm
Vendor

subscribe