Insufficient argument checking in Secure state Entry...
Moderate severity
Unreviewed
Published
Apr 24, 2024
to the GitHub Advisory Database
•
Updated Aug 9, 2024
Description
Published by the National Vulnerability Database
Apr 24, 2024
Published to the GitHub Advisory Database
Apr 24, 2024
Last updated
Aug 9, 2024
Insufficient argument checking in Secure state Entry functions in software using Cortex-M Security Extensions (CMSE), that has been compiled using toolchains that implement 'Arm v8-M Security Extensions Requirements on Development Tools' prior to version 1.4, allows an attacker to pass values to Secure state that are out of range for types smaller than 32-bits. Out of range values might lead to incorrect operations in secure state due.
References