CVE-2021-43619
Description
Trusted Firmware M 1.4.x through 1.4.1 contains a stack buffer overflow in the Firmware Update partition, allowing SPE or NSPE callers to overwrite stack memory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Trusted Firmware M 1.4.x through 1.4.1 contains a stack buffer overflow in the Firmware Update partition, allowing SPE or NSPE callers to overwrite stack memory.
Vulnerability
Trusted Firmware M versions 1.4.x through 1.4.1 contain a buffer overflow vulnerability within the Firmware Update partition. This issue occurs in the IPC model, where a psa_fwu_write caller originating from either the Secure Processing Environment (SPE) or Non-secure Processing Environment (NSPE) can overwrite stack memory locations [1].
Exploitation
An attacker with the ability to call the psa_fwu_write function from either the SPE or NSPE could trigger this vulnerability. The specific conditions or prerequisites for an attacker to gain this calling capability are not detailed in the available references [1, 2].
Impact
Successful exploitation of this buffer overflow vulnerability allows an attacker to overwrite stack memory. This could lead to a denial-of-service condition or potentially allow for arbitrary code execution within the context of the firmware update process, depending on the specific overwrite achieved [1].
Mitigation
Trusted Firmware M versions 1.4.x through 1.4.1 are affected. A fix for this vulnerability has been released in Trusted Firmware M version 1.5.0, which was made available on December 15, 2021 [1]. Users are advised to update to version 1.5.0 or later. No workarounds are described in the available references [2].
AI Insight generated on Jun 5, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Trusted Firmware/Trusted Firmware Mdescription
- Range: 1.4.x - 1.4.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- tf-m-user-guide.trustedfirmware.org/docs/security/security_advisories/fwu_write_vulnerability.htmlnvdExploitPatchThird Party Advisory
- developer.arm.com/support/arm-security-updatesnvdVendor Advisory
- www.trustedfirmware.orgnvdProduct
News mentions
0No linked articles in our index yet.