Executive brief
Caliptra Core Runtime Firmware is used to provide a secure foundation for hardware systems. A security flaw in how the firmware handles certain commands allows a local user with basic privileges to crash the system or cause it to stop responding. This could lead to a total service outage or require a manual reset of the affected hardware.
Technical details
A missing authorization vulnerability exists in Caliptra Core Runtime Firmware version 2.1.0 when operating in subsystem mode. The affected commands—INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, and EXTERNAL_MAILBOX_CMD—perform DMA reads or writes using unverified AXI addresses provided within the command. A local attacker with low privileges can exploit this by providing an invalid or unauthorized AXI address, causing the system to attempt an invalid DMA access. This typically results in a system hang (Denial of Service), though further impacts to system integrity may occur depending on the specific hardware integration. The issue is addressed in version 2.1.1.
Affected products
- Caliptra Core Runtime Firmware 2.1.0
Timeline
- 2026-07-22: advisory
- 2026-07-22: disclosed
- 2026-07-22: patched: Fixed in version 2.1.1