CVE-2022-47630

NameCVE-2022-47630
DescriptionTrusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects downstream use of get_ext and auth_nvctr. Attackers might be able to trigger dangerous read side effects or obtain sensitive information about microarchitectural state.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
arm-trusted-firmware (PTS)buster2.0+290.98aab974-2vulnerable
bullseye2.4+dfsg-2vulnerable
bookworm2.8.0+dfsg-1vulnerable
sid, trixie2.10.0+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
arm-trusted-firmwaresource(unstable)2.9.0+dfsg-3unimportant

Notes

https://www.openwall.com/lists/oss-security/2023/01/16/8
Debian ships an almost unpatched copy, so is not affected by itself
Still tracking for the purpose of potential downstream providers
https://github.com/ARM-software/arm-trusted-firmware/commit/fd37982a19a4a291 (v2.9-rc0)
https://github.com/ARM-software/arm-trusted-firmware/commit/72460f50e2437a85 (v2.9-rc0)
https://github.com/ARM-software/arm-trusted-firmware/commit/f5c51855d36e399e (v2.9-rc0)
https://github.com/ARM-software/arm-trusted-firmware/commit/abb8f936fd0ad085 (v2.9-rc0)

Search for package or bug name: Reporting problems