CVE-2023-31339
medium
CVSS v3
5.8
CVSS v4 NEW
—
VIR risk
5.8
Description
Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged attacker to perform out of bound reads, potentially resulting in data leakage and denial of service.
Predictions
Exploit likelihood
58%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
✚ Propose a mitigation on Community → Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| amd | zu11eg | - | |
| amd | zu15eg | - | |
| amd | zu17eg | - | |
| amd | zu19eg | - | |
| amd | zu1cg | - | |
| amd | zu1eg | - | |
| amd | zu21dr | - | |
| amd | zu25dr | - | |
| amd | zu27dr | - | |
| amd | zu28dr | - | |
| amd | zu29dr | - | |
| amd | zu2cg | - | |
| amd | zu2eg | - | |
| amd | zu39dr | - | |
| amd | zu3cg | - | |
| amd | zu3eg | - | |
| amd | zu3tcg | - | |
| amd | zu3teg | - | |
| amd | zu42dr | - | |
| amd | zu43dr | - | |
| amd | zu46dr | - | |
| amd | zu47dr | - | |
| amd | zu48dr | - | |
| amd | zu49dr | - | |
| amd | zu4cg | - | |
| amd | zu4eg | - | |
| amd | zu4ev | - | |
| amd | zu5cg | - | |
| amd | zu5eg | - | |
| amd | zu5ev | - | |
| amd | zu63dr | - | |
| amd | zu64dr | - | |
| amd | zu65dr | - | |
| amd | zu67dr | - | |
| amd | zu6cg | - | |
| amd | zu6eg | - | |
| amd | zu7cg | - | |
| amd | zu7eg | - | |
| amd | zu7ev | - | |
| amd | zu9cg | - | |
| amd | zu9eg | - | |
| amd | trusted_firmware-a | {"endExcluding":"2023.2"} | 2023.2 |
References
CWEs
CWE-20 CWE-125
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.