CVE-2020-11684

Source
https://cve.org/CVERecord?id=CVE-2020-11684
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-11684.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-11684
Published
2020-09-14T14:15:10.680Z
Modified
2026-07-08T16:28:50.073704Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

AT91bootstrap before 3.9.2 does not properly wipe encryption and authentication keys from memory before passing control to a less privileged software component. This can be exploited to disclose these keys and subsequently encrypt and sign the next boot stage (such as the bootloader).

References

Affected packages

Git / github.com/linux4sam/at91bootstrap

Affected ranges

Type
GIT
Repo
https://github.com/linux4sam/at91bootstrap
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:linux4sam:at91bootstrap:*:*:*:*:*:*:*:*",
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "3.7.2"
        },
        {
            "fixed": "3.9.2"
        }
    ]
}

Affected versions

linux4sam_5.*
linux4sam_5.6-rc1
v3.*
v3.7.2
v3.8
v3.8-alpha1
v3.8-alpha2
v3.8-alpha3
v3.8-alpha4
v3.8-alpha5
v3.8-alpha6
v3.8-alpha7
v3.8-beta1
v3.8.1
v3.8.10
v3.8.10-rc1
v3.8.11
v3.8.11-rc1
v3.8.11-rc2
v3.8.11-rc3
v3.8.11-rc4
v3.8.12
v3.8.13
v3.8.13-rc1
v3.8.13-rc2
v3.8.13-rc3
v3.8.13-rc4
v3.8.13-rc5
v3.8.2
v3.8.3
v3.8.4
v3.8.5
v3.8.6
v3.8.7
v3.8.8
v3.8.8-rc2
v3.8.8-rc3
v3.8.9
v3.8.9-rc1
v3.8.9-rc2
v3.8.9-rc3
v3.8.9-rc4
v3.8.9-rc6
v3.8.9-rc7
v3.9.0
v3.9.0-rc1
v3.9.0-rc2
v3.9.0-rc3
v3.9.0-rc4
v3.9.0-rc5
v3.9.1
v3.9.1-rc1
v3.9.2
v3.9.2-rc1
v3.9.2-rc2

Database specific

vanir_signatures_modified
"2026-07-08T16:28:50Z"
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-11684.json"
vanir_signatures
[
    {
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "length": 1345.0,
            "function_hash": "200692050760140054223115041198207933150"
        },
        "id": "CVE-2020-11684-0473e789",
        "source": "https://github.com/linux4sam/at91bootstrap/commit/45419497309ffbf27c17ea7938499aca99168927",
        "target": {
            "function": "init_keys",
            "file": "driver/secure.c"
        }
    },
    {
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "length": 826.0,
            "function_hash": "153428154091827794769738504096631208817"
        },
        "id": "CVE-2020-11684-103ffd55",
        "source": "https://github.com/linux4sam/at91bootstrap/commit/45419497309ffbf27c17ea7938499aca99168927",
        "target": {
            "function": "secure_decrypt",
            "file": "driver/secure.c"
        }
    },
    {
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "90771419695632574893041257732495704985",
                "121844745475223443586111716810301676940",
                "276448386987870808248079057713410613336",
                "94094918496943873620396238788549065076",
                "114421871720338896600133664545819823963",
                "69583370425854558461947445970244377407",
                "22126993293021106677478645184240171693",
                "108137508694407852794986101817768258784",
                "327797473611254948806279551750363158775",
                "141544167034528888097181683341438554973",
                "210726726237448859972476344939712694929",
                "113332244469197106724184779456629841554",
                "198425084357507786973054051631747477540",
                "134164019716009848817715455760717056847",
                "305728889847710414100739616732937860830",
                "9172878133091353684164199975778451932",
                "175869230148785236478068353347306296750",
                "72357208598596214624994671835336787817",
                "167255571264388727799244046411855167562",
                "99013593338971482539505720306383298891",
                "164971587725216606576815453772270532839",
                "141419820788703685062440499862947042236",
                "49590527038122564115720212773325578173",
                "181051906505077408096085293177391368573",
                "144486398217911779508654866604162532130",
                "269490306362159957845290877826934357065",
                "106351053643369912557426074351669507540",
                "264957995521947034565673607870045018397",
                "171065663074957967245762612476648391426",
                "277320208124275488208877815284971397798",
                "21307688812890837586121111323188193683",
                "223165042052661145975980944258172758701",
                "64317648349737908140699216424572560572",
                "227945261061435914106914344335975820493",
                "110040752745467303554100251518541882821",
                "314767499504593830615702746023241937479",
                "300097784998663770967905160403963897482",
                "58699618846117310615615417898255871015",
                "10645262197692334164139397262755368376",
                "225814473473048958902799299203936795547",
                "101073161328786268179382789738135404901",
                "181383117432574019090244051452968668975",
                "195717626159765951006002122782813545022",
                "31351996932469303443875471175914839255",
                "170718235183767858962966410998123588195",
                "326809121035194660669313033476183859649",
                "242057171821916926143854670754258253771",
                "90734774775535583817659747273535711225",
                "199853711146915740808781120466130819866",
                "193080849732736961967125399711392579898",
                "69132496007725629938627564495725179684",
                "288189898844354819387430322851848321791",
                "65227199591439756166822398882284810597",
                "159810849813000704311423868679338513864",
                "206475447119595701767236686423202944644",
                "331201725888283545691621652005578825095",
                "212180262919716284536099118354122498421",
                "69146115625270334375991584452536142170",
                "55280400358412258222894891897920464915",
                "217235950073330951605193999376918225572",
                "6554739832172336096270202671346273776",
                "1364672997025395902747037341540199889",
                "116710164813831529094664923556559017557",
                "297108400410891784055244646940216340344",
                "48311965499784860861081105420570857974",
                "62585818777068268345667104601806752624",
                "131833136674351959082832508002103637743",
                "126132397537878871343594551897895209453",
                "222125784807018582415470857511012180639"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2020-11684-196a3d52",
        "source": "https://github.com/linux4sam/at91bootstrap/commit/45419497309ffbf27c17ea7938499aca99168927",
        "target": {
            "file": "driver/secure.c"
        }
    },
    {
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "122709445779356478262488462098520234652",
                "7867556566203589828494404608005299276",
                "87320999566895698176461107988393859603"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2020-11684-1bd95be5",
        "source": "https://github.com/linux4sam/at91bootstrap/commit/45419497309ffbf27c17ea7938499aca99168927",
        "target": {
            "file": "include/secure.h"
        }
    },
    {
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "length": 321.0,
            "function_hash": "244496785881977350995589051485898840438"
        },
        "id": "CVE-2020-11684-4c0e5d6d",
        "source": "https://github.com/linux4sam/at91bootstrap/commit/45419497309ffbf27c17ea7938499aca99168927",
        "target": {
            "function": "secure_check",
            "file": "driver/secure.c"
        }
    }
]