CVE-2022-47630

NameCVE-2022-47630
DescriptionTrusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects downstream use of get_ext and auth_nvctr. Attackers might be able to trigger dangerous read side effects or obtain sensitive information about microarchitectural state.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
arm-trusted-firmware (PTS)buster2.0+290.98aab974-2vulnerable
bullseye2.4+dfsg-2vulnerable
bookworm2.8.0+dfsg-1vulnerable
sid, trixie2.9.0+dfsg-3vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
arm-trusted-firmwaresource(unstable)(unfixed)unimportant

Notes

https://www.openwall.com/lists/oss-security/2023/01/16/8
Debian ships an almost unpatched copy, so is not affected by itself
Still tracking for the purpose of potential downstream providers

Search for package or bug name: Reporting problems