CVE-2021-43619

Trusted Firmware M 1.4.x through 1.4.1 has a buffer overflow issue in the Firmware Update partition. In the IPC model, a psa_fwu_write caller from SPE or NSPE can overwrite stack memory locations.

high 7.8 CVSS 3.1
Published: Mar 1, 2022
Modified: Jun 5, 2026
Vendor: Trustedfirmware
Product: Trusted Firmware-M
Versions: 1.4.0,1.4.1

Description

Trusted Firmware M 1.4.x through 1.4.1 has a buffer overflow issue in the Firmware Update partition. In the IPC model, a psa_fwu_write caller from SPE or NSPE can overwrite stack memory locations.

References

Related CVEs