PT-2026-78520 · Rockchip · Rk3588S Soc Bootrom

·

CVE-2024-13942

·

Published

2026-08-19

·

Updated

2026-08-19

CVSS v3.1

7.6

High

VectorAV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RK3588s SoC BootROM (secure) version 350B20210512V100
Description The Secure BootROM of the RK3588s SoC is susceptible to a time-of-check to time-of-use (TOCTOU) attack when booting from external media such as SPI NOR, NAND, EMMC, or SD. The issue occurs because the system reads the next-stage loader header twice: first partially to obtain hashes of executable modules, and second fully to verify the header signature. While the signature is verified using the complete data, the authenticity of the executable modules is validated against the partial data from the first read. An attacker with physical access can use an emulator or a circuit with a multiplexer to modify the loader data on-the-fly, potentially leading to arbitrary code execution with EL3 privileges.
Recommendations For RK3588s SoC BootROM (secure) version 350B20210512V100, apply mitigations according to vendor instructions or discontinue use of the product if mitigations are unavailable.

Fix

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-13942

Affected Products

Rk3588S Soc Bootrom