7 CVE-2026-54467
On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidated, supplied pointer.
https://nvd.nist.gov/vuln/detail/CVE-2026-54467
Categories
CWE-283 : Unverified Ownership
The product does not properly verify that a critical resource is owned by the proper entity. Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software. Consider following the principle of separation of privilege. Require multiple conditions to be met before permitting access to a system resource. Program does not verify the owner of a UNIX socket that is used for sending a password. Owner of special device not checked, allowing root.
References
AFFECTED (from MITRE)
| Vendor |
Product |
Versions |
| TrustedFirmware |
Trusted Firmware-M |
- < 00d1b3e716dc636f7ad4398980ae55427dc1731d [affected]
|
| © 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. |
CPE
| cpe |
start |
end |
| Configuration 1 |
| cpe:2.3:a:trustedfirmware:trusted_firmware-m:*:*:*:*:*:*:*:* |
|
< 00d1b3e716dc636f7ad4398980ae55427dc1731d |
REMEDIATION
EXPLOITS
Exploit-db.com
| id |
description |
date |
|
| No known exploits |
POC Github
Other Nist (github, ...)
CAPEC
Common Attack Pattern Enumerations and Classifications
| id |
description |
severity |
| No entry |
Cybersecurity needs ?
Strengthen software security from the outset with our DevSecOps expertise
Integrate security right from the start of the software development cycle for more robust applications and greater customer confidence.
Our team of DevSecOps experts can help you secure your APIs, data pipelines, CI/CD chains, Docker containers and Kubernetes deployments.
Discover this offer