CVE-2016-10319: Arm Trusted Firmware Project Arm Trusted Firmware
Medium severity, CVSS 5.9. EPSS: 1.6% chance of exploitation in the next 30 days.
In ARM Trusted Firmware 1.2 and 1.3, a malformed firmware update SMC can result in copying unexpectedly large data into secure memory because of integer overflows. This affects certain cases involving execution of both AArch64 Generic Trusted Firmware (TF) BL1 code and other firmware update code.
Affected products
- Arm Trusted Firmware Project Arm Trusted Firmware: version 1.2 only; version 1.3 only
Published 2017-04-06. Last modified 2026-06-17.