Out-of-Bounds Read Vulnerability in Altera Trusted Firmware
CVE-2026-58004

8.3HIGH

Key Information:

Vendor

Altera

Vendor
CVE Published:
24 September 2026

What is CVE-2026-58004?

An out-of-bounds read vulnerability exists in Altera Trusted Firmware on HPS, which can lead to privilege escalation and buffer overflow issues. This vulnerability allows attackers to exploit memory management flaws within the firmware, compromising system integrity and potentially granting unauthorized access to system resources. Users of affected versions, particularly socfpga_v2.14.0, should take immediate action to mitigate risks by applying any available updates or patches.

Affected Version(s)

Trusted Firmware ARM 0

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.