CVE-2026-13466
Received Received - Intake

Buffer Overflow in Altera Trusted Firmware HPS

Vulnerability report for CVE-2026-13466, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: Altera

Description

Incorrect calculation of buffer size vulnerability in Altera Trusted Firmware on HPS allows Overflow Buffers. This issue affects Trusted Firmware: through socfpga_v2.14.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-24
AI Q&A
2026-09-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
altera trusted_firmware to 2.14.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-131 The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves an incorrect calculation of buffer size in Altera Trusted Firmware on HPS, which can lead to buffer overflows. It affects Trusted Firmware versions up to and including socfpga_v2.14.0.

Detection Guidance

Detection requires checking the version of Altera Trusted Firmware on HPS. Compare installed version against socfpga_v2.14.0. Use system commands like 'cat /path/to/firmware/version' or vendor-specific tools to verify firmware version.

Impact Analysis

A buffer overflow could allow attackers to execute arbitrary code, escalate privileges, or cause system crashes. Since it affects trusted firmware, it may compromise system integrity and security.

Mitigation Strategies

Update Altera Trusted Firmware to a version beyond socfpga_v2.14.0. Follow vendor advisories for patch installation. Ensure secure boot configurations are enforced and monitor for unusual buffer overflow indicators.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13466. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart