diff mbox series

[1/1] arm-bsp/trusted-firmware-m: corstone1000: backport Corstone-1000 security fixes

Message ID 20260929143200.2244035-2-harsimransingh.tungal@arm.com
State New
Headers show
Series arm-bsp/trusted-firmware-m: corstone1000: backport Corstone-1000 security fixes | expand

Commit Message

Harsimran Singh Tungal Sept. 29, 2026, 2:32 p.m. UTC
Backport two TF-M security fixes for the Corstone-1000 platform.

The fixes address vulnerabilities in the TF-M firmware and keep the
platform aligned with upstream TF-M security updates.

Signed-off-by: Harsimran Singh Tungal <harsimransingh.tungal@arm.com>
---
 ...-Fix-missing-destination-offset-of-p.patch | 92 +++++++++++++++++++
 ...Bound-FWU-writes-to-target-partition.patch | 61 ++++++++++++
 .../trusted-firmware-m-corstone1000.inc       |  2 +
 3 files changed, 155 insertions(+)
 create mode 100644 meta-arm-bsp/recipes-bsp/trusted-firmware-m/files/corstone1000/0017-corstone1000-fwu-Fix-missing-destination-offset-of-p.patch
 create mode 100644 meta-arm-bsp/recipes-bsp/trusted-firmware-m/files/corstone1000/0018-plat-cs1k-Bound-FWU-writes-to-target-partition.patch
diff mbox series

Patch

diff --git a/meta-arm-bsp/recipes-bsp/trusted-firmware-m/files/corstone1000/0017-corstone1000-fwu-Fix-missing-destination-offset-of-p.patch b/meta-arm-bsp/recipes-bsp/trusted-firmware-m/files/corstone1000/0017-corstone1000-fwu-Fix-missing-destination-offset-of-p.patch
new file mode 100644
index 00000000..8d898110
--- /dev/null
+++ b/meta-arm-bsp/recipes-bsp/trusted-firmware-m/files/corstone1000/0017-corstone1000-fwu-Fix-missing-destination-offset-of-p.patch
@@ -0,0 +1,92 @@ 
+From b3a51b202020ea461b5e742c3cdf6db02deef757 Mon Sep 17 00:00:00 2001
+From: Nicola Mazzucato <nicola.mazzucato@arm.com>
+Date: Tue, 7 Jul 2026 17:19:37 +0100
+Subject: [PATCH 17/18] corstone1000: fwu: Fix missing destination offset of
+ parse_fmp_header
+
+parse_fmp_header() overwrites the beginning of fmp_hdr on every FWU write.
+Fix it by appending incoming partial header bytes.
+
+Also:
+ - use local variables to improve readability
+ - add an overflow check for the incoming size before memcpy
+
+CVE: CVE-2026-73063
+Upstream-Status: Backport [d92781c5b966ee700ddaa9525230e677789def96]
+Signed-off-by: Nicola Mazzucato <nicola.mazzucato@arm.com>
+Change-Id: Iefcfe1c9c2479ea4346a56ecb0475483a56ee695
+---
+ .../bootloader/mcuboot/tfm_mcuboot_fwu.c      | 43 ++++++++++++++-----
+ 1 file changed, 33 insertions(+), 10 deletions(-)
+
+diff --git a/platform/ext/target/arm/corstone1000/bootloader/mcuboot/tfm_mcuboot_fwu.c b/platform/ext/target/arm/corstone1000/bootloader/mcuboot/tfm_mcuboot_fwu.c
+index 9fe9df0a4..83db6163c 100644
+--- a/platform/ext/target/arm/corstone1000/bootloader/mcuboot/tfm_mcuboot_fwu.c
++++ b/platform/ext/target/arm/corstone1000/bootloader/mcuboot/tfm_mcuboot_fwu.c
+@@ -1863,26 +1863,46 @@ out:
+     return ret;
+ }
+ 
+-psa_status_t parse_fmp_header(psa_fwu_component_t component, const void *block, size_t size, size_t *fmp_bytes)
++static psa_status_t parse_fmp_header(
++    psa_fwu_component_t component,
++    const void *block,
++    size_t size,
++    size_t *fmp_bytes)
+ {
++    size_t header_size = sizeof(fmp_header_image_info[component].fmp_hdr);
++    size_t *header_size_recv = &fmp_header_image_info[component].fmp_hdr_size_recvd;
++
++    if ((*header_size_recv + size) < size) {
++        return PSA_ERROR_INVALID_ARGUMENT;
++    }
++
+     /* Parse the incoming block to make sure complete FMP header is received */
+-    if (sizeof(fmp_header_image_info[component].fmp_hdr) >= (fmp_header_image_info[component].fmp_hdr_size_recvd + size)) {
+-        memcpy(&fmp_header_image_info[component].fmp_hdr, block, size);
+-        fmp_header_image_info[component].fmp_hdr_size_recvd += size;
++    if (header_size >= (*header_size_recv + size)) {
++        memcpy(
++            (uint8_t *)&fmp_header_image_info[component].fmp_hdr + *header_size_recv,
++            block,
++            size);
++
+         *fmp_bytes = size;
++        *header_size_recv += size;
++
+         return PSA_ERROR_INSUFFICIENT_DATA;
+     }
+-    if (fmp_header_image_info[component].fmp_hdr_size_recvd != sizeof(fmp_header_image_info[component].fmp_hdr)) {
+-        memcpy(&fmp_header_image_info[component].fmp_hdr,
+-                block,
+-                (sizeof(fmp_header_image_info[component].fmp_hdr) - fmp_header_image_info[component].fmp_hdr_size_recvd));
++    if (*header_size_recv != header_size) {
++        memcpy(
++            (uint8_t *)&fmp_header_image_info[component].fmp_hdr + *header_size_recv,
++            block,
++            (header_size - *header_size_recv));
++
++        *fmp_bytes = header_size - *header_size_recv;
++        *header_size_recv = header_size;
+ 
+-        *fmp_bytes = sizeof(fmp_header_image_info[component].fmp_hdr) - fmp_header_image_info[component].fmp_hdr_size_recvd;
+-        fmp_header_image_info[component].fmp_hdr_size_recvd = sizeof(fmp_header_image_info[component].fmp_hdr);
+         return PSA_SUCCESS;
+     }
+ 
++    FWU_ASSERT(0);
+ }
++
+ psa_status_t fwu_bootloader_load_image(psa_fwu_component_t component,
+                                        size_t block_offset,
+                                        const void *block,
+@@ -1925,6 +1945,9 @@ psa_status_t fwu_bootloader_load_image(psa_fwu_component_t component,
+         if(ret == PSA_ERROR_INSUFFICIENT_DATA) {
+             return PSA_SUCCESS;
+         }
++        if(ret == PSA_ERROR_INVALID_ARGUMENT) {
++            return ret;
++        }
+         if (ret == PSA_SUCCESS) {
+             block_size -= fmp_bytes;
+             block += fmp_bytes;
diff --git a/meta-arm-bsp/recipes-bsp/trusted-firmware-m/files/corstone1000/0018-plat-cs1k-Bound-FWU-writes-to-target-partition.patch b/meta-arm-bsp/recipes-bsp/trusted-firmware-m/files/corstone1000/0018-plat-cs1k-Bound-FWU-writes-to-target-partition.patch
new file mode 100644
index 00000000..8b1f5eb3
--- /dev/null
+++ b/meta-arm-bsp/recipes-bsp/trusted-firmware-m/files/corstone1000/0018-plat-cs1k-Bound-FWU-writes-to-target-partition.patch
@@ -0,0 +1,61 @@ 
+From 3de39fdc1cdc2f446c57d9211f20252612673733 Mon Sep 17 00:00:00 2001
+From: Harsimran Singh Tungal <harsimransingh.tungal@arm.com>
+Date: Fri, 7 Aug 2026 12:01:58 +0100
+Subject: [PATCH 18/18] plat: cs1k: Bound FWU writes to target partition
+
+The Corstone-1000 FWU bootloader backend writes update blocks directly
+to flash using ProgramData(). Unlike the generic TF-M FWU backend, this
+path does not go through flash_area_write(), so partition overflow checks
+are not applied.
+
+Reject FWU write requests that would exceed the flash address space or
+the target image partition size before calling the raw flash driver.
+
+This prevents any host from writing past the selected update
+partition into other secure flash regions.
+
+CVE: CVE-2026-73094
+Upstream-Status: Backport [060ec25948f29f66b026be3c4858c2dbdfe0c443]
+Signed-off-by: Harsimran Singh Tungal <harsimransingh.tungal@arm.com>
+Signed-off-by: Nicola Mazzucato <nicola.mazzucato@arm.com>
+Change-Id: I2f4ceeab93014cbbfcd91fb865c167bbaa290b3d
+---
+ .../bootloader/mcuboot/tfm_mcuboot_fwu.c      | 25 +++++++++++++++++++
+ 1 file changed, 25 insertions(+)
+
+diff --git a/platform/ext/target/arm/corstone1000/bootloader/mcuboot/tfm_mcuboot_fwu.c b/platform/ext/target/arm/corstone1000/bootloader/mcuboot/tfm_mcuboot_fwu.c
+index 9fe9df0a4..2e0d742e3 100644
+--- a/platform/ext/target/arm/corstone1000/bootloader/mcuboot/tfm_mcuboot_fwu.c
++++ b/platform/ext/target/arm/corstone1000/bootloader/mcuboot/tfm_mcuboot_fwu.c
+@@ -2024,6 +2024,31 @@ psa_status_t fwu_bootloader_load_image(psa_fwu_component_t component,
+     image_offset = part.start * TFM_GPT_BLOCK_SIZE;
+ #endif /* BL1_BUILD */
+ 
++    if ((fmp_header_image_info[fwu_image_index].image_size_recvd >
++            (UINT32_MAX - image_offset)) ||
++        (block_size > (UINT32_MAX - image_offset -
++            fmp_header_image_info[fwu_image_index].image_size_recvd))) {
++        FWU_LOG_MSG("%s: image write range overflows flash address space\n\r", __func__);
++        ret = PSA_ERROR_INVALID_ARGUMENT;
++        goto out;
++    }
++
++#ifdef BL1_BUILD
++    if ((fmp_header_image_info[fwu_image_index].image_size_recvd >
++            fwu_image[fwu_image_index].image_size) ||
++        (block_size > (fwu_image[fwu_image_index].image_size -
++            fmp_header_image_info[fwu_image_index].image_size_recvd))) {
++#else
++    if ((fmp_header_image_info[fwu_image_index].image_size_recvd >
++            (part.size * TFM_GPT_BLOCK_SIZE)) ||
++        (block_size > ((part.size * TFM_GPT_BLOCK_SIZE) -
++            fmp_header_image_info[fwu_image_index].image_size_recvd))) {
++#endif
++        FWU_LOG_MSG("%s: image write exceeds partition size\n\r", __func__);
++        ret = PSA_ERROR_INSUFFICIENT_STORAGE;
++        goto out;
++    }
++
+     /* Firmware update process can only start in regular state. */
+     current_state = get_fwu_image_state(&_metadata, &priv_metadata, fwu_image_index);
+     if (current_state != PSA_FWU_READY) {
diff --git a/meta-arm-bsp/recipes-bsp/trusted-firmware-m/trusted-firmware-m-corstone1000.inc b/meta-arm-bsp/recipes-bsp/trusted-firmware-m/trusted-firmware-m-corstone1000.inc
index 3422163d..fbf1daf6 100644
--- a/meta-arm-bsp/recipes-bsp/trusted-firmware-m/trusted-firmware-m-corstone1000.inc
+++ b/meta-arm-bsp/recipes-bsp/trusted-firmware-m/trusted-firmware-m-corstone1000.inc
@@ -51,6 +51,8 @@  SRC_URI:append:corstone1000 = " \
     file://0014-plat-cs1k-Duplicate-old-images-in-FWU.patch \
     file://0015-platform-corstone1000-Increase-FIP-partition-size.patch \
     file://0016-platform-corstone1000-Optionally-skip-provisioning.patch \
+    file://0017-corstone1000-fwu-Fix-missing-destination-offset-of-p.patch \
+    file://0018-plat-cs1k-Bound-FWU-writes-to-target-partition.patch \
     "
 
 FILESEXTRAPATHS:prepend:corstone1000-mps3 := "${THISDIR}/files/corstone1000/psa-adac:"