CVE-2026-7328
Received Received - Intake

Missing Authorization in Caliptra Core Runtime Firmware

Vulnerability report for CVE-2026-7328, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-22

Last updated on: 2026-07-22

Assigner: b01ddd03-5ef6-483b-b2c5-acba77f1a554

Description

Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CMD commands) in subsystem mode allows a privileged local attacker to cause a denial of service via mailbox commands containing unverified AXI addresses. The security impact beyond availability is integration-specific. This issue affects Core Runtime Firmware: 2.1.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-22
Last Modified
2026-07-22
Generated
2026-07-22
AI Q&A
2026-07-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
chipsalliance caliptra_core_runtime_firmware to 2.1.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves missing authorization checks in Caliptra Core Runtime Firmware when running in subsystem mode. Certain commands (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CMD) accept unverified AXI addresses for DMA operations. This allows privileged local attackers to trigger invalid memory access, potentially causing system hangs or crashes.

Detection Guidance

Detecting this vulnerability requires checking for unauthorized mailbox commands or DMA operations using unverified AXI addresses. Monitor Caliptra logs for INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, or EXTERNAL_MAILBOX_CMD commands with invalid addresses. Use system monitoring tools to detect unexpected DMA transfers or system hangs.

Impact Analysis

The primary impact is denial of service due to system hangs or crashes caused by invalid DMA accesses. Attackers with local access and low privileges could exploit this without user interaction. Confidentiality and integrity impacts are minimal as the issue mainly affects availability.

Compliance Impact

The vulnerability primarily impacts system availability through potential denial of service, which may indirectly affect compliance with standards like GDPR or HIPAA by disrupting data processing or access. However, the CVE description does not explicitly link this issue to specific compliance violations or data protection requirements.

Mitigation Strategies

Upgrade Caliptra Core Runtime Firmware to version 2.1.1 or later to patch the vulnerability. If upgrading is not immediately possible, restrict local access to privileged users and monitor for suspicious mailbox commands or DMA operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-7328. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart