PT-2026-97828 · Altera · Trusted Firmware On Hps

CVE-2026-58004

·

Published

2026-09-24

·

Updated

2026-09-24

CVSS v3.1

8.1

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions Altera Trusted Firmware on HPS versions prior to socfpga v2.14.0
Description An out-of-bounds read issue occurs when a crafted oversized firmware image is processed, leading to an EL3 stack overflow during VAB authentication. This can result in buffer overflows and privilege escalation. EL3 refers to the highest exception level in ARM architecture, typically reserved for the Secure Monitor.
Recommendations Update Altera Trusted Firmware on HPS to a version newer than socfpga v2.14.0.

Fix

LPE

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58004

Affected Products

Trusted Firmware On Hps