{"id":"CVE-2020-11684","details":"AT91bootstrap before 3.9.2 does not properly wipe encryption and authentication keys from memory before passing control to a less privileged software component. This can be exploited to disclose these keys and subsequently encrypt and sign the next boot stage (such as the bootloader).","modified":"2026-07-08T16:28:50.073704Z","published":"2020-09-14T14:15:10.680Z","references":[{"type":"FIX","url":"https://github.com/linux4sam/at91bootstrap/commit/45419497309ffbf27c17ea7938499aca99168927"},{"type":"EVIDENCE","url":"https://labs.f-secure.com/advisories/microchip-at91bootstrap/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/linux4sam/at91bootstrap","events":[{"introduced":"533f4082e35869ab61d1112f518063aa0496febb"},{"fixed":"959a75951a8a8feddef210470cb9aca2c9bdcb5a"},{"fixed":"45419497309ffbf27c17ea7938499aca99168927"}],"database_specific":{"cpe":"cpe:2.3:a:linux4sam:at91bootstrap:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.7.2"},{"fixed":"3.9.2"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v3.9.2","v3.9.2-rc2","v3.9.2-rc1","v3.9.1","v3.9.1-rc1","v3.9.0","v3.9.0-rc5","v3.9.0-rc4","v3.9.0-rc3","v3.9.0-rc2","v3.9.0-rc1","v3.8.13","v3.8.13-rc5","v3.8.13-rc4","v3.8.13-rc3","v3.8.13-rc2","v3.8.13-rc1","v3.8.12","v3.8.11","v3.8.11-rc4","v3.8.11-rc3","v3.8.11-rc1","v3.8.11-rc2","v3.8.10","v3.8.10-rc1","v3.8.9","v3.8.9-rc7","v3.8.9-rc6","v3.8.9-rc4","v3.8.9-rc3","v3.8.9-rc2","v3.8.9-rc1","v3.8.8","v3.8.8-rc3","v3.8.8-rc2","linux4sam_5.6-rc1","v3.8.7","v3.8.6","v3.8.5","v3.8.4","v3.8.3","v3.8.2","v3.8.1","v3.8","v3.8-beta1","v3.8-alpha7","v3.8-alpha6","v3.8-alpha5","v3.8-alpha4","v3.8-alpha3","v3.8-alpha2","v3.8-alpha1","v3.7.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-11684.json","vanir_signatures_modified":"2026-07-08T16:28:50Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"200692050760140054223115041198207933150","length":1345},"id":"CVE-2020-11684-0473e789","signature_type":"Function","signature_version":"v1","source":"https://github.com/linux4sam/at91bootstrap/commit/45419497309ffbf27c17ea7938499aca99168927","target":{"file":"driver/secure.c","function":"init_keys"}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/linux4sam/at91bootstrap/commit/45419497309ffbf27c17ea7938499aca99168927","target":{"file":"driver/secure.c","function":"secure_decrypt"},"deprecated":false,"digest":{"function_hash":"153428154091827794769738504096631208817","length":826},"id":"CVE-2020-11684-103ffd55"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/linux4sam/at91bootstrap/commit/45419497309ffbf27c17ea7938499aca99168927","target":{"file":"driver/secure.c"},"deprecated":false,"digest":{"line_hashes":["90771419695632574893041257732495704985","121844745475223443586111716810301676940","276448386987870808248079057713410613336","94094918496943873620396238788549065076","114421871720338896600133664545819823963","69583370425854558461947445970244377407","22126993293021106677478645184240171693","108137508694407852794986101817768258784","327797473611254948806279551750363158775","141544167034528888097181683341438554973","210726726237448859972476344939712694929","113332244469197106724184779456629841554","198425084357507786973054051631747477540","134164019716009848817715455760717056847","305728889847710414100739616732937860830","9172878133091353684164199975778451932","175869230148785236478068353347306296750","72357208598596214624994671835336787817","167255571264388727799244046411855167562","99013593338971482539505720306383298891","164971587725216606576815453772270532839","141419820788703685062440499862947042236","49590527038122564115720212773325578173","181051906505077408096085293177391368573","144486398217911779508654866604162532130","269490306362159957845290877826934357065","106351053643369912557426074351669507540","264957995521947034565673607870045018397","171065663074957967245762612476648391426","277320208124275488208877815284971397798","21307688812890837586121111323188193683","223165042052661145975980944258172758701","64317648349737908140699216424572560572","227945261061435914106914344335975820493","110040752745467303554100251518541882821","314767499504593830615702746023241937479","300097784998663770967905160403963897482","58699618846117310615615417898255871015","10645262197692334164139397262755368376","225814473473048958902799299203936795547","101073161328786268179382789738135404901","181383117432574019090244051452968668975","195717626159765951006002122782813545022","31351996932469303443875471175914839255","170718235183767858962966410998123588195","326809121035194660669313033476183859649","242057171821916926143854670754258253771","90734774775535583817659747273535711225","199853711146915740808781120466130819866","193080849732736961967125399711392579898","69132496007725629938627564495725179684","288189898844354819387430322851848321791","65227199591439756166822398882284810597","159810849813000704311423868679338513864","206475447119595701767236686423202944644","331201725888283545691621652005578825095","212180262919716284536099118354122498421","69146115625270334375991584452536142170","55280400358412258222894891897920464915","217235950073330951605193999376918225572","6554739832172336096270202671346273776","1364672997025395902747037341540199889","116710164813831529094664923556559017557","297108400410891784055244646940216340344","48311965499784860861081105420570857974","62585818777068268345667104601806752624","131833136674351959082832508002103637743","126132397537878871343594551897895209453","222125784807018582415470857511012180639"],"threshold":0.9},"id":"CVE-2020-11684-196a3d52"},{"source":"https://github.com/linux4sam/at91bootstrap/commit/45419497309ffbf27c17ea7938499aca99168927","target":{"file":"include/secure.h"},"deprecated":false,"digest":{"line_hashes":["122709445779356478262488462098520234652","7867556566203589828494404608005299276","87320999566895698176461107988393859603"],"threshold":0.9},"id":"CVE-2020-11684-1bd95be5","signature_type":"Line","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/linux4sam/at91bootstrap/commit/45419497309ffbf27c17ea7938499aca99168927","target":{"file":"driver/secure.c","function":"secure_check"},"deprecated":false,"digest":{"function_hash":"244496785881977350995589051485898840438","length":321},"id":"CVE-2020-11684-4c0e5d6d","signature_type":"Function"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}