OESA-2023-1899
Dashboard / Vulnerabilities / OESA-2023-1899
Summary: arm-trusted-firmware security update
Details: Trusted Firmware-A is a reference implementation of secure world software for Arm A-Profile architectures (Armv8-A and Armv7-A), including an Exception Level 3 (EL3) Secure Monitor. Security Fix(es): Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects downstream use of get_ext and auth_nvctr. Attackers might be able to trigger dangerous read side effects or obtain sensitive information about microarchitectural state.(CVE-2022-47630)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2023-1899, https://nvd.nist.gov/vuln/detail/CVE-2022-47630
Affected packages
Package
Name: arm-trusted-firmware
Purl: pkg:rpm/openEuler/arm-trusted-firmware&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
