{"id":"UBUNTU-CVE-2023-49100","details":"Trusted Firmware-A (TF-A) before 2.10 has a potential read out-of-bounds in the SDEI service. The input parameter passed in register x1 is not validated well enough in the function sdei_interrupt_bind. The parameter is passed to a call to plat_ic_get_interrupt_type. It can be any arbitrary value passing checks in the function plat_ic_is_sgi. A compromised Normal World (Linux kernel) can enable a root-privileged attacker to issue arbitrary SMC calls. Using this primitive, he can control the content of registers x0 through x6, which are used to send parameters to TF-A. Out-of-bounds addresses can be read in the context of TF-A (EL3). Because the read value is never returned to non-secure memory or in registers, no leak is possible. An attacker can still crash TF-A, however.","modified":"2025-10-24T05:02:21Z","published":"2024-02-21T16:15:00Z","upstream":["CVE-2023-49100"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-49100"},{"type":"REPORT","url":"https://trustedfirmware-a.readthedocs.io/en/latest/security_advisories/security-advisory-tfv-11.html"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2023-49100"}],"affected":[{"package":{"name":"arm-trusted-firmware","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/arm-trusted-firmware@2.2-2?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.1-3","2.2-2"],"ecosystem_specific":{"binaries":[{"binary_name":"arm-trusted-firmware","binary_version":"2.2-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-49100.json"}},{"package":{"name":"arm-trusted-firmware","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/arm-trusted-firmware@2.6+dfsg-1?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.5+dfsg-1","2.6+dfsg-1"],"ecosystem_specific":{"binaries":[{"binary_name":"arm-trusted-firmware","binary_version":"2.6+dfsg-1"},{"binary_name":"arm-trusted-firmware-tools","binary_version":"2.6+dfsg-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-49100.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}