Known Vulnerabilities for Core Firmware by Caliptra
Listed below are 10 of the newest known vulnerabilities associated with "Core Firmware" by "Caliptra".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-64511 json | In the Linux kernel, the following vulnerability has been resolved: ACPI: NFIT: core: Fix possible NULL pointer dereference ... | Not Provided | 2026-07-25 | 2026-07-25 |
| CVE-2026-43151 json | In the Linux kernel, the following vulnerability has been resolved: Revert "media: iris: Add sanity check for stop streaming... | Not Provided | 2026-05-06 | 2026-05-11 |
| CVE-2026-43145 json | In the Linux kernel, the following vulnerability has been resolved: remoteproc: imx_rproc: Fix invalid loaded resource table... | Not Provided | 2026-05-06 | 2026-05-11 |
| CVE-2026-14985 json | The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the core ... | Not Provided | 2026-07-22 | 2026-07-27 |
| CVE-2026-11836 json | Insufficient verification of data authenticity in Caliptra Core ROM and Core Firmware (validate_debug_unlock_token()) in subs... | Not Provided | 2026-08-04 | 2026-08-04 |
| CVE-2026-11835 json | Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateResetFlow... | Not Provided | 2026-08-04 | 2026-08-04 |
| CVE-2026-7328 json | Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CMD com... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-6458 json | Missing cryptographic step in Caliptra Core Firmware (aes_256_gcm_update module) results in an incorrect GCM authentication t... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-5818 json | Incorrect check of function return value in Caliptra Core Runtime Firmware (ActivateFirmwareCmd::activate_fw modules) allows ... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2025-38601 json | In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: clear initialized flag for deinit-ed srng ... | Not Provided | 2025-08-19 | 2026-07-30 |