CVE-2026-54467

Summary

On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidated, supplied pointer.

Affected Software

VendorProductVersion RangeStatus
TrustedFirmwareTrusted Firmware-M0 < 00d1b3e716dc636f7ad4398980ae55427dc1731daffected

Weaknesses

  • CWE-283: CWE-283 Unverified Ownership

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References