CVE-2026-54467
Deferred Deferred - Pending Action

Mailbox Pointer Validation Flaw in Trusted Firmware-M

Vulnerability report for CVE-2026-54467, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-26

Last updated on: 2026-09-09

Assigner: MITRE

Description

On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidated, supplied pointer.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-26
Last Modified
2026-09-09
Generated
2026-09-15
AI Q&A
2026-08-26
EPSS Evaluated
2026-09-14
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
trusted_firmware_m tf-m to 2.3.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-283 The product does not properly verify that a critical resource is owned by the proper entity.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in Trusted Firmware-M (TF-M) versions 2 through 2.3.0. It involves improper handling of a pointer during mailbox initialization on PSOC64 and RP2350 platforms. A non-secure, unvalidated pointer is accepted, which could allow unauthorized access or manipulation of memory.

Detection Guidance

Detection requires checking TF-M versions and mailbox initialization behavior. Inspect TF-M logs for unexpected pointer handling during mailbox setup. Review system memory access patterns for unauthorized secure memory access attempts. No direct commands are provided in available resources.

Impact Analysis

This vulnerability could allow an attacker with local access and limited privileges to escalate their access level. It may lead to unauthorized code execution, data breaches, or system compromise on affected devices using TF-M versions 2 through 2.3.0.

Compliance Impact

This vulnerability allows non-secure code to supply unvalidated pointers during mailbox initialization, potentially leading to unauthorized memory access or code execution. Such flaws could compromise data integrity and confidentiality, which are critical for compliance with GDPR (data protection) and HIPAA (healthcare data privacy). However, the provided CVE details do not explicitly address compliance impacts.

Mitigation Strategies

Update Trusted Firmware-M to version 2.3.0 or later to address the mailbox initialization issue. Ensure secure validation of pointers in PSOC64 and RP2350 platforms.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54467. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart