PT-2026-78520 · Rockchip · Rk3588S Soc Bootrom
CVSS v3.1
7.6
High
| Vector | AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RK3588s SoC BootROM (secure) version 350B20210512V100
Description
The Secure BootROM of the RK3588s SoC is susceptible to a time-of-check to time-of-use (TOCTOU) attack when booting from external media such as SPI NOR, NAND, EMMC, or SD. The issue occurs because the system reads the next-stage loader header twice: first partially to obtain hashes of executable modules, and second fully to verify the header signature. While the signature is verified using the complete data, the authenticity of the executable modules is validated against the partial data from the first read. An attacker with physical access can use an emulator or a circuit with a multiplexer to modify the loader data on-the-fly, potentially leading to arbitrary code execution with EL3 privileges.
Recommendations
For RK3588s SoC BootROM (secure) version 350B20210512V100, apply mitigations according to vendor instructions or discontinue use of the product if mitigations are unavailable.
Fix
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rk3588S Soc Bootrom