All 8 CVE vulnerabilities found in Trusted Firmware, with AI-generated Chinese analysis, references, and POCs.
Vendor: Altera
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-58008 | Unchecked HKDF key-size input in EL3 causes a stack buffer overflow CWE-121 | 8.1 | High | 2026-09-24 |
| CVE-2026-58007 | Unchecked SDM mailbox response address enables EL3 secure-memory corruption CWE-822 | 8.1 | High | 2026-09-24 |
| CVE-2026-58006 | Altera SoCFPGA BL31 Mailbox Output Pointer Validation Enables EL3 Secure-Memory Corruption CWE-822 | 8.1 | High | 2026-09-24 |
| CVE-2026-58005 | Unvalidated SiP v2 mailbox pointers allow non-secure EL1 access to arbitrary physical addresses through EL3. CWE-119 | 8.1 | High | 2026-09-24 |
| CVE-2026-58004 | Crafted oversized firmware image causes EL3 stack overflow during VAB authentication on Trusted Firmware. CWE-125 | 8.1 | High | 2026-09-24 |
| CVE-2026-13467 | Systemic Missing Address Validation in SiP SMC Handlers CWE-787 | 8.1 | High | 2026-09-24 |
| CVE-2026-13466 | Unit Confusion in VAB Authentication CWE-131 | 8.1 | High | 2026-09-24 |
| CVE-2026-13465 | EL3 Stack Buffer Overflow in FCS HKDF Request CWE-121 | 8.1 | High | 2026-09-24 |
All 8 known CVE vulnerabilities affecting Trusted Firmware with full Chinese analysis, references, and POCs where available.