CVE-2020-16273

Severity CVSS v4.0:
Pending analysis
Type:
CWE-191 Integer Underflow (Wrap or Wraparound)
Publication date:
12/11/2020
Last modified:
01/12/2020

Description

In Arm software implementing the Armv8-M processors (all versions), the stack selection mechanism could be influenced by a stack-underflow attack in v8-M TrustZone based processors. An attacker can cause a change to the stack pointer used by the Secure World from a non-secure application if the stack is not initialized. This vulnerability affects only the software that is based on Armv8-M processors with the Security Extension.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:arm:armv8-m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:arm:armv8-m:-:*:*:*:*:*:*:*