CVE-2026-102709
Awaiting Analysis Awaiting Analysis - Queue

Improper Pointer Validation in TrustZone-M NSC Functions

Vulnerability report for CVE-2026-102709, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Eclipse Foundation

Description

Improper validation of non-secure (NS) pointers in multiple TrustZone-M non-secure callable (NSC) entry functions allows an attacker executing in the non-secure world to supply pointers to secure memory. The secure firmware subsequently dereferences these attacker-controlled pointers without verifying that they reference non-secure memory, resulting in unintended disclosure of secure memory contents. This violates the isolation guarantees provided by Arm TrustZone-M and can be leveraged as a memory disclosure or corruption primitive that may enable recovery of sensitive cryptographic material.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-822 The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-501 The product mixes trusted and untrusted data in the same data structure or structured message.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper validation of non-secure pointers in TrustZone-M non-secure callable entry functions. An attacker in the non-secure world can provide pointers to secure memory, which the secure firmware then dereferences without checking if they point to non-secure memory. This allows unintended disclosure of secure memory contents, breaking TrustZone-M's isolation guarantees and potentially enabling memory disclosure or corruption attacks.

Impact Analysis

This vulnerability could allow attackers to read sensitive secure memory contents, including cryptographic material. If exploited, it may lead to unauthorized access to confidential data, compromise of secure applications, or further attacks leveraging exposed secrets. The impact depends on the specific use of TrustZone-M in your system.

Compliance Impact

This vulnerability could violate compliance with GDPR, HIPAA, and other regulations requiring strong data protection and isolation. Unauthorized disclosure of secure memory contents may result in data breaches, leading to legal penalties, reputational damage, and loss of trust. Organizations must address this to maintain regulatory compliance.

Mitigation Strategies

Update TrustZone-M firmware to a patched version that validates non-secure pointers in NSC entry functions. Review and restrict non-secure world access to secure memory regions. Implement runtime checks to ensure pointers from non-secure memory do not reference secure memory.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102709. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart