Improper Pointer Validation in Arm TrustZone-M by Eclipse
CVE-2026-102709

8.4HIGH

Key Information:

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-102709?

The vulnerability relates to improper validation of non-secure pointers in various TrustZone-M non-secure callable entry functions. Attackers operating in the non-secure environment can exploit this flaw by supplying pointers that reference secure memory. When the secure firmware dereferences these pointers without adequate verification, it leads to unintended leakage of sensitive data from secure memory. This breach undermines the isolation mechanisms of Arm TrustZone-M and potentially allows for the extraction of confidential cryptographic materials.

Affected Version(s)

ThreadX 0 <= 6.5.1.202602

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

jovanbulck
btijs
martonbognar
antonislouca
.