Improper Pointer Validation in Arm TrustZone-M by Eclipse
CVE-2026-102709
8.4HIGH
What is CVE-2026-102709?
The vulnerability relates to improper validation of non-secure pointers in various TrustZone-M non-secure callable entry functions. Attackers operating in the non-secure environment can exploit this flaw by supplying pointers that reference secure memory. When the secure firmware dereferences these pointers without adequate verification, it leads to unintended leakage of sensitive data from secure memory. This breach undermines the isolation mechanisms of Arm TrustZone-M and potentially allows for the extraction of confidential cryptographic materials.
Affected Version(s)
ThreadX 0 <= 6.5.1.202602
