← back
CVE-2026-58004highCWE-125

Crafted oversized firmware image causes EL3 stack overflow during VAB authentication on Trusted Firmware.

18Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.3
exploitation probability
—
observed exploitation
nono source reports it
Out-of-bounds read vulnerability in Altera Trusted Firmware on HPS allows Privilege Escalation and Overflow Buffers. This issue affects Trusted Firmware: through socfpga_v2.14.0.
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H