VulnerabilityModified
CVE-2016-10319
In ARM Trusted Firmware 1.2 and 1.3, a malformed firmware update SMC can result in copying unexpectedly large data into secure memory because of integer overflows.
MEDIUM 5.9EPSS 1.60%
Does this matter?
Lower severity and a low EPSS score (1.60%). Track it; it rarely justifies an emergency change on its own.
Description
In ARM Trusted Firmware 1.2 and 1.3, a malformed firmware update SMC can result in copying unexpectedly large data into secure memory because of integer overflows. This affects certain cases involving execution of both AArch64 Generic Trusted Firmware (TF) BL1 code and other firmware update code.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.60% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190
- Affected
- arm trusted firmware project/arm trusted firmware
- Source
- cve@mitre.org
References
- https://github.com/ARM-software/arm-trusted-firmware/wiki/ARM-Trusted-Firmware-Security-Advisory-TFV-1Issue Tracking, Patch, VDB Entry
- https://github.com/ARM-software/arm-trusted-firmware/wiki/ARM-Trusted-Firmware-Security-Advisory-TFV-1Issue Tracking, Patch, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.