PT-2026-97828 · Altera · Trusted Firmware On Hps
CVE-2026-58004
·
Published
2026-09-24
·
Updated
2026-09-24
CVSS v3.1
8.1
High
| Vector | AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Altera Trusted Firmware on HPS versions prior to socfpga v2.14.0
Description
An out-of-bounds read issue occurs when a crafted oversized firmware image is processed, leading to an EL3 stack overflow during VAB authentication. This can result in buffer overflows and privilege escalation. EL3 refers to the highest exception level in ARM architecture, typically reserved for the Secure Monitor.
Recommendations
Update Altera Trusted Firmware on HPS to a version newer than socfpga v2.14.0.
Fix
LPE
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trusted Firmware On Hps