CVE-2016-10319

MEDIUM

Arm Trusted Firmware - Integer Overflow

Title source: rule

Description

In ARM Trusted Firmware 1.2 and 1.3, a malformed firmware update SMC can result in copying unexpectedly large data into secure memory because of integer overflows. This affects certain cases involving execution of both AArch64 Generic Trusted Firmware (TF) BL1 code and other firmware update code.

Scores

CVSS v3 5.9
EPSS 0.0044
EPSS Percentile 62.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Classification

CWE
CWE-190
Status published

Affected Products (3)

arm_trusted_firmware_project/arm_trusted_firmware
arm_trusted_firmware_project/arm_trusted_firmware
n/a/n/a

Timeline

Published Apr 06, 2017
Tracked Since Feb 18, 2026