Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects downstream use of get_ext and auth_nvctr. Attackers might be able to trigger dangerous read side effects or obtain sensitive information about microarchitectural state.
Metrics
Affected Vendors & Products
References
History
Tue, 08 Apr 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 27 Nov 2024 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:o:arm:trusted_firmware-a:*:*:*:*:*:*:*:* |

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-08T20:26:30.379Z
Reserved: 2022-12-20T00:00:00.000Z
Link: CVE-2022-47630

Updated: 2024-08-03T15:02:36.318Z

Status : Modified
Published: 2023-01-16T16:15:10.940
Modified: 2025-04-08T21:15:44.903
Link: CVE-2022-47630

No data.