UBUNTU-CVE-2022-47630
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-47630
Summary:
Details: Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects downstream use of get_ext and auth_nvctr. Attackers might be able to trigger dangerous read side effects or obtain sensitive information about microarchitectural state.
References: https://ubuntu.com/security/CVE-2022-47630, https://www.trustedfirmware.org/news/, https://trustedfirmware-a.readthedocs.io/en/latest/security_advisories/security-advisory-tfv-10.html, http://www.openwall.com/lists/oss-security/2023/01/16/8, https://www.cve.org/CVERecord?id=CVE-2022-47630
Affected packages
Package
Name: arm-trusted-firmware
Purl: pkg:deb/ubuntu/arm-trusted-firmware?arch=source&distro=focal
Affected ranges
Type: ECOSYSTEM
Events:
