Junglewise Threat Intelligence

CVE-2026-7328: Caliptra Core Runtime Firmware missing authorization in mailbox commands

CVE-2026-7328 · Severity: info · CVSS 6.8 · Published 2026-07-22

Technologies: CHIPS Alliance Core Runtime Firmware. Vendors: CHIPS Alliance.

Executive brief

Caliptra Core Runtime Firmware is used to provide a secure foundation for hardware systems. A security flaw in how the firmware handles certain commands allows a local user with basic privileges to crash the system or cause it to stop responding. This could lead to a total service outage or require a manual reset of the affected hardware.

Technical details

A missing authorization vulnerability exists in Caliptra Core Runtime Firmware version 2.1.0 when operating in subsystem mode. The affected commands—INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, and EXTERNAL_MAILBOX_CMD—perform DMA reads or writes using unverified AXI addresses provided within the command. A local attacker with low privileges can exploit this by providing an invalid or unauthorized AXI address, causing the system to attempt an invalid DMA access. This typically results in a system hang (Denial of Service), though further impacts to system integrity may occur depending on the specific hardware integration. The issue is addressed in version 2.1.1.

Affected products

  • Caliptra Core Runtime Firmware 2.1.0

Timeline

  • 2026-07-22: advisory
  • 2026-07-22: disclosed
  • 2026-07-22: patched: Fixed in version 2.1.1

References

Related threats