OESA-2023-1899

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2023-1899
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2023-1899.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2023-1899
Upstream
Published
2023-12-08T11:06:26Z
Modified
2025-08-12T05:16:15.749346Z
Summary
arm-trusted-firmware security update
Details

Trusted Firmware-A is a reference implementation of secure world software for Arm A-Profile architectures (Armv8-A and Armv7-A), including an Exception Level 3 (EL3) Secure Monitor.

Security Fix(es):

Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects downstream use of getext and authnvctr. Attackers might be able to trigger dangerous read side effects or obtain sensitive information about microarchitectural state.(CVE-2022-47630)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:20.03-LTS-SP1 / arm-trusted-firmware

Package

Name
arm-trusted-firmware
Purl
pkg:rpm/openEuler/arm-trusted-firmware&distro=openEuler-20.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6-3.oe1

Ecosystem specific

{
    "aarch64": [
        "arm-trusted-firmware-armv8-1.6-3.oe1.aarch64.rpm"
    ],
    "src": [
        "arm-trusted-firmware-1.6-3.oe1.src.rpm"
    ]
}

openEuler:20.03-LTS-SP3 / arm-trusted-firmware

Package

Name
arm-trusted-firmware
Purl
pkg:rpm/openEuler/arm-trusted-firmware&distro=openEuler-20.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6-3.oe1

Ecosystem specific

{
    "aarch64": [
        "arm-trusted-firmware-armv8-1.6-3.oe1.aarch64.rpm"
    ],
    "src": [
        "arm-trusted-firmware-1.6-3.oe1.src.rpm"
    ]
}

openEuler:22.03-LTS / arm-trusted-firmware

Package

Name
arm-trusted-firmware
Purl
pkg:rpm/openEuler/arm-trusted-firmware&distro=openEuler-22.03-LTS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.3-3.oe2203sp2

Ecosystem specific

{
    "aarch64": [
        "arm-trusted-firmware-armv8-2.3-2.oe2203.aarch64.rpm",
        "arm-trusted-firmware-armv8-2.3-3.oe2203sp1.aarch64.rpm",
        "arm-trusted-firmware-armv8-2.3-3.oe2203sp2.aarch64.rpm"
    ],
    "src": [
        "arm-trusted-firmware-2.3-2.oe2203.src.rpm",
        "arm-trusted-firmware-2.3-3.oe2203sp1.src.rpm",
        "arm-trusted-firmware-2.3-3.oe2203sp2.src.rpm"
    ]
}

openEuler:22.03-LTS-SP1 / arm-trusted-firmware

Package

Name
arm-trusted-firmware
Purl
pkg:rpm/openEuler/arm-trusted-firmware&distro=openEuler-22.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.3-3.oe2203sp1

Ecosystem specific

{
    "aarch64": [
        "arm-trusted-firmware-armv8-2.3-3.oe2203sp1.aarch64.rpm"
    ],
    "src": [
        "arm-trusted-firmware-2.3-3.oe2203sp1.src.rpm"
    ]
}

openEuler:22.03-LTS-SP2 / arm-trusted-firmware

Package

Name
arm-trusted-firmware
Purl
pkg:rpm/openEuler/arm-trusted-firmware&distro=openEuler-22.03-LTS-SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.3-3.oe2203sp2

Ecosystem specific

{
    "aarch64": [
        "arm-trusted-firmware-armv8-2.3-3.oe2203sp2.aarch64.rpm"
    ],
    "src": [
        "arm-trusted-firmware-2.3-3.oe2203sp2.src.rpm"
    ]
}