Vulnerability in Mailbox Initialization on Trusted Firmware-M for PSOC64 and RP2350
CVE-2026-54467

7HIGH

Key Information:

Vendor
CVE Published:
26 August 2026

What is CVE-2026-54467?

The Trusted Firmware-M platforms, specifically versions 2.0 to 2.3.0 before commit 00d1b3e, exhibit a flaw in the mailbox initialization process on PSOC64 and RP2350. This vulnerability arises from the acceptance of a non-secure, unvalidated pointer, which could potentially allow unauthorized access to sensitive data or provide an attack vector for malicious exploits. It is crucial for developers utilizing these platforms to address this issue to mitigate the risks associated with improper input validation.

Affected Version(s)

Trusted Firmware-M 0 < 00d1b3e716dc636f7ad4398980ae55427dc1731d

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.