CVE-2026-102709 TrustZone-M 非安全指针验证不当漏洞
影响非安全世界攻击者可读取安全内存敏感数据
TrustZone-M 的多个非安全可调用(NSC)入口函数未正确校验非安全(NS)指针,导致安全固件会解引用攻击者提供的指向安全内存的指针。该缺陷破坏了 TrustZone-M 的安全隔离保证,可被用作内存泄露或破坏原语,进而可能恢复敏感密码学材料。
影响范围
影响使用 TrustZone-M 且 NSC 入口函数未校验 NS 指针的 Arm 平台安全固件;具体受影响芯片、SDK 与版本范围暂无公开信息。
漏洞详情
漏洞类型为指针验证不当导致的安全内存越界读取。成因是 NSC 入口函数在接收非安全世界传入的指针参数时,未验证其是否确实指向非安全内存区域。攻击者在非安全世界构造指向安全内存的指针并调用这些入口,安全固件随后解引用该指针,从而泄露安全内存内容。
利用条件与风险
利用前提是攻击者能在非安全世界执行代码并调用受影响的 NSC 入口函数,无需额外权限。实战中可导致安全内存泄露,若泄露内容包含密钥等敏感材料,可能进一步危及设备信任根。
修复建议
官方修复方案为在 NSC 入口函数中对所有来自非安全世界的指针进行严格校验,确保其指向非安全内存;具体补丁与版本信息暂无公开信息。临时缓解措施包括限制非安全世界调用面、加强指针校验与内存隔离审计。
Improper validation of non-secure (NS) pointers in multiple TrustZone-M non-secure callable (NSC) entry functions allows an attacker executing in the non-secure world to supply pointers to secure memory. The secure firmware subsequently dereferences these attacker-controlled pointers without verifying that they reference non-secure memory, resulting in unintended disclosure of secure memory contents. This violates the isolation guarantees provided by Arm TrustZone-M and can be leveraged as a memory disclosure or corruption primitive that may enable recovery of sensitive cryptographic material.