Trusted Firmware-A is a reference implementation of secure world software for Arm A-Profile architectures (Armv8-A and Armv7-A), including an Exception Level 3 (EL3) Secure Monitor.
Security Fix(es):
Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects downstream use of get_ext and auth_nvctr. Attackers might be able to trigger dangerous read side effects or obtain sensitive information about microarchitectural state.(CVE-2022-47630)
{
"severity": "High"
}{
"aarch64": [
"arm-trusted-firmware-armv8-2.3-2.oe2203.aarch64.rpm",
"arm-trusted-firmware-armv8-2.3-3.oe2203sp1.aarch64.rpm",
"arm-trusted-firmware-armv8-2.3-3.oe2203sp2.aarch64.rpm"
],
"src": [
"arm-trusted-firmware-2.3-2.oe2203.src.rpm",
"arm-trusted-firmware-2.3-3.oe2203sp1.src.rpm",
"arm-trusted-firmware-2.3-3.oe2203sp2.src.rpm"
]
}