Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2021-40327: firmware-m.git - Trusted Firmware for M profile Arm CPUs

Trusted Firmware-M (TF-M) 1.4.0, when Profile Small is used, has incorrect access control. NSPE can access a secure key (held by the Crypto service) based solely on knowledge of its key ID. For example, there is no authorization check associated with the relationship between a caller and a key owner.

CVE
#git

Branch

Commit message

Author

Age

TF-Mv1.1-stack-seal-mitigation

SPM: Add a panic after NS jumping

Ken Liu

15 months

TF-Mv1.4.x

Docs: Update version to v1.4.1

David Hu

4 months

feature-cc-psa-crypto-drivers

Crypto: Fix checkpatch issues

Antonio de Angelis

26 hours

feature-fih

SPM: Refine list operations

Ken Liu

11 months

feature-fwu-partition

Build: Fetch tf-m-tests repo with fixed version

Kevin Peng

12 months

feature-isolation-level3

Test: Add a negative test case for level 3 in tf-m part.

Shawn Shan

15 months

feature-psa-dev-api-update

SST: Implement PSA Protected Storage 1.0

Galanakis, Minos

2 years

feature-ux-buildsystem

Platform: stm32l5xx: Create a dedicated stm_tool.py

Michel Jaouen

18 months

master

Crypto: Upgrade Mbed TLS to v3.1.0

Summer Qin

34 hours

release/1.5.x

Docs: Release notes for v1.5.0

Anton Komlev

6 weeks

[…]

Tag

Download

Author

Age

TF-Mv1.5.0

trusted-firmware-m-TF-Mv1.5.0.tar.gz

Anton Komlev

6 weeks

TF-Mv1.5.0-RC2

trusted-firmware-m-TF-Mv1.5.0-RC2.tar.gz

Anton Komlev

7 weeks

TF-Mv1.5.0-RC1

trusted-firmware-m-TF-Mv1.5.0-RC1.tar.gz

Anton Komlev

8 weeks

TF-Mv1.4.1

trusted-firmware-m-TF-Mv1.4.1.tar.gz

Anton Komlev

4 months

TF-Mv1.4.0

trusted-firmware-m-TF-Mv1.4.0.tar.gz

Anton Komlev

5 months

TF-Mv1.4.0-RC3

trusted-firmware-m-TF-Mv1.4.0-RC3.tar.gz

Anton Komlev

6 months

TF-Mv1.4.0-RC2

trusted-firmware-m-TF-Mv1.4.0-RC2.tar.gz

Summer Qin

6 months

TF-Mv1.4.0-RC1

trusted-firmware-m-TF-Mv1.4.0-RC1.tar.gz

Anton Komlev

6 months

TF-Mv1.3.0

trusted-firmware-m-TF-Mv1.3.0.tar.gz

Anton Komlev

9 months

TF-Mv1.3.0-RC3

trusted-firmware-m-TF-Mv1.3.0-RC3.tar.gz

Karl Zhang

9 months

[…]

Age

Commit message

Author

34 hours

Crypto: Upgrade Mbed TLS to v3.1.0HEADmaster

Summer Qin

34 hours

Docs: Clean up build instructions

Chris Brand

38 hours

SPM: AAPCS-specific operations

Ken Liu

39 hours

SPM: Remove unused field in service_t struct

Sherry Zhang

46 hours

platform: lairdconnectivity: Add platform GPIO and read service

Joakim Andersson

3 days

Crypto: Return correctly PSA_ERROR_INVALID_HANDLE

Antonio de Angelis

3 days

Build: Fix warning in IPC mode

Antonio de Angelis

6 days

Docs: Fix incorrect project version generation.

Anton Komlev

8 days

Platform: PSoC64: Add support for SLIH tests

Chris Brand

13 days

SPM: Rename ‘thread call’ with ‘cross call’

Xinyu Zhang

[…]

Clone

https://git.trustedfirmware.org/TF-M/trusted-firmware-m.git

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907