new file mode 100644
@@ -0,0 +1,92 @@
+From b3a51b202020ea461b5e742c3cdf6db02deef757 Mon Sep 17 00:00:00 2001
+From: Nicola Mazzucato <nicola.mazzucato@arm.com>
+Date: Tue, 7 Jul 2026 17:19:37 +0100
+Subject: [PATCH 17/18] corstone1000: fwu: Fix missing destination offset of
+ parse_fmp_header
+
+parse_fmp_header() overwrites the beginning of fmp_hdr on every FWU write.
+Fix it by appending incoming partial header bytes.
+
+Also:
+ - use local variables to improve readability
+ - add an overflow check for the incoming size before memcpy
+
+CVE: CVE-2026-73063
+Upstream-Status: Backport [d92781c5b966ee700ddaa9525230e677789def96]
+Signed-off-by: Nicola Mazzucato <nicola.mazzucato@arm.com>
+Change-Id: Iefcfe1c9c2479ea4346a56ecb0475483a56ee695
+---
+ .../bootloader/mcuboot/tfm_mcuboot_fwu.c | 43 ++++++++++++++-----
+ 1 file changed, 33 insertions(+), 10 deletions(-)
+
+diff --git a/platform/ext/target/arm/corstone1000/bootloader/mcuboot/tfm_mcuboot_fwu.c b/platform/ext/target/arm/corstone1000/bootloader/mcuboot/tfm_mcuboot_fwu.c
+index 9fe9df0a4..83db6163c 100644
+--- a/platform/ext/target/arm/corstone1000/bootloader/mcuboot/tfm_mcuboot_fwu.c
++++ b/platform/ext/target/arm/corstone1000/bootloader/mcuboot/tfm_mcuboot_fwu.c
+@@ -1863,26 +1863,46 @@ out:
+ return ret;
+ }
+
+-psa_status_t parse_fmp_header(psa_fwu_component_t component, const void *block, size_t size, size_t *fmp_bytes)
++static psa_status_t parse_fmp_header(
++ psa_fwu_component_t component,
++ const void *block,
++ size_t size,
++ size_t *fmp_bytes)
+ {
++ size_t header_size = sizeof(fmp_header_image_info[component].fmp_hdr);
++ size_t *header_size_recv = &fmp_header_image_info[component].fmp_hdr_size_recvd;
++
++ if ((*header_size_recv + size) < size) {
++ return PSA_ERROR_INVALID_ARGUMENT;
++ }
++
+ /* Parse the incoming block to make sure complete FMP header is received */
+- if (sizeof(fmp_header_image_info[component].fmp_hdr) >= (fmp_header_image_info[component].fmp_hdr_size_recvd + size)) {
+- memcpy(&fmp_header_image_info[component].fmp_hdr, block, size);
+- fmp_header_image_info[component].fmp_hdr_size_recvd += size;
++ if (header_size >= (*header_size_recv + size)) {
++ memcpy(
++ (uint8_t *)&fmp_header_image_info[component].fmp_hdr + *header_size_recv,
++ block,
++ size);
++
+ *fmp_bytes = size;
++ *header_size_recv += size;
++
+ return PSA_ERROR_INSUFFICIENT_DATA;
+ }
+- if (fmp_header_image_info[component].fmp_hdr_size_recvd != sizeof(fmp_header_image_info[component].fmp_hdr)) {
+- memcpy(&fmp_header_image_info[component].fmp_hdr,
+- block,
+- (sizeof(fmp_header_image_info[component].fmp_hdr) - fmp_header_image_info[component].fmp_hdr_size_recvd));
++ if (*header_size_recv != header_size) {
++ memcpy(
++ (uint8_t *)&fmp_header_image_info[component].fmp_hdr + *header_size_recv,
++ block,
++ (header_size - *header_size_recv));
++
++ *fmp_bytes = header_size - *header_size_recv;
++ *header_size_recv = header_size;
+
+- *fmp_bytes = sizeof(fmp_header_image_info[component].fmp_hdr) - fmp_header_image_info[component].fmp_hdr_size_recvd;
+- fmp_header_image_info[component].fmp_hdr_size_recvd = sizeof(fmp_header_image_info[component].fmp_hdr);
+ return PSA_SUCCESS;
+ }
+
++ FWU_ASSERT(0);
+ }
++
+ psa_status_t fwu_bootloader_load_image(psa_fwu_component_t component,
+ size_t block_offset,
+ const void *block,
+@@ -1925,6 +1945,9 @@ psa_status_t fwu_bootloader_load_image(psa_fwu_component_t component,
+ if(ret == PSA_ERROR_INSUFFICIENT_DATA) {
+ return PSA_SUCCESS;
+ }
++ if(ret == PSA_ERROR_INVALID_ARGUMENT) {
++ return ret;
++ }
+ if (ret == PSA_SUCCESS) {
+ block_size -= fmp_bytes;
+ block += fmp_bytes;
new file mode 100644
@@ -0,0 +1,61 @@
+From 3de39fdc1cdc2f446c57d9211f20252612673733 Mon Sep 17 00:00:00 2001
+From: Harsimran Singh Tungal <harsimransingh.tungal@arm.com>
+Date: Fri, 7 Aug 2026 12:01:58 +0100
+Subject: [PATCH 18/18] plat: cs1k: Bound FWU writes to target partition
+
+The Corstone-1000 FWU bootloader backend writes update blocks directly
+to flash using ProgramData(). Unlike the generic TF-M FWU backend, this
+path does not go through flash_area_write(), so partition overflow checks
+are not applied.
+
+Reject FWU write requests that would exceed the flash address space or
+the target image partition size before calling the raw flash driver.
+
+This prevents any host from writing past the selected update
+partition into other secure flash regions.
+
+CVE: CVE-2026-73094
+Upstream-Status: Backport [060ec25948f29f66b026be3c4858c2dbdfe0c443]
+Signed-off-by: Harsimran Singh Tungal <harsimransingh.tungal@arm.com>
+Signed-off-by: Nicola Mazzucato <nicola.mazzucato@arm.com>
+Change-Id: I2f4ceeab93014cbbfcd91fb865c167bbaa290b3d
+---
+ .../bootloader/mcuboot/tfm_mcuboot_fwu.c | 25 +++++++++++++++++++
+ 1 file changed, 25 insertions(+)
+
+diff --git a/platform/ext/target/arm/corstone1000/bootloader/mcuboot/tfm_mcuboot_fwu.c b/platform/ext/target/arm/corstone1000/bootloader/mcuboot/tfm_mcuboot_fwu.c
+index 9fe9df0a4..2e0d742e3 100644
+--- a/platform/ext/target/arm/corstone1000/bootloader/mcuboot/tfm_mcuboot_fwu.c
++++ b/platform/ext/target/arm/corstone1000/bootloader/mcuboot/tfm_mcuboot_fwu.c
+@@ -2024,6 +2024,31 @@ psa_status_t fwu_bootloader_load_image(psa_fwu_component_t component,
+ image_offset = part.start * TFM_GPT_BLOCK_SIZE;
+ #endif /* BL1_BUILD */
+
++ if ((fmp_header_image_info[fwu_image_index].image_size_recvd >
++ (UINT32_MAX - image_offset)) ||
++ (block_size > (UINT32_MAX - image_offset -
++ fmp_header_image_info[fwu_image_index].image_size_recvd))) {
++ FWU_LOG_MSG("%s: image write range overflows flash address space\n\r", __func__);
++ ret = PSA_ERROR_INVALID_ARGUMENT;
++ goto out;
++ }
++
++#ifdef BL1_BUILD
++ if ((fmp_header_image_info[fwu_image_index].image_size_recvd >
++ fwu_image[fwu_image_index].image_size) ||
++ (block_size > (fwu_image[fwu_image_index].image_size -
++ fmp_header_image_info[fwu_image_index].image_size_recvd))) {
++#else
++ if ((fmp_header_image_info[fwu_image_index].image_size_recvd >
++ (part.size * TFM_GPT_BLOCK_SIZE)) ||
++ (block_size > ((part.size * TFM_GPT_BLOCK_SIZE) -
++ fmp_header_image_info[fwu_image_index].image_size_recvd))) {
++#endif
++ FWU_LOG_MSG("%s: image write exceeds partition size\n\r", __func__);
++ ret = PSA_ERROR_INSUFFICIENT_STORAGE;
++ goto out;
++ }
++
+ /* Firmware update process can only start in regular state. */
+ current_state = get_fwu_image_state(&_metadata, &priv_metadata, fwu_image_index);
+ if (current_state != PSA_FWU_READY) {
@@ -51,6 +51,8 @@ SRC_URI:append:corstone1000 = " \
file://0014-plat-cs1k-Duplicate-old-images-in-FWU.patch \
file://0015-platform-corstone1000-Increase-FIP-partition-size.patch \
file://0016-platform-corstone1000-Optionally-skip-provisioning.patch \
+ file://0017-corstone1000-fwu-Fix-missing-destination-offset-of-p.patch \
+ file://0018-plat-cs1k-Bound-FWU-writes-to-target-partition.patch \
"
FILESEXTRAPATHS:prepend:corstone1000-mps3 := "${THISDIR}/files/corstone1000/psa-adac:"
Backport two TF-M security fixes for the Corstone-1000 platform. The fixes address vulnerabilities in the TF-M firmware and keep the platform aligned with upstream TF-M security updates. Signed-off-by: Harsimran Singh Tungal <harsimransingh.tungal@arm.com> --- ...-Fix-missing-destination-offset-of-p.patch | 92 +++++++++++++++++++ ...Bound-FWU-writes-to-target-partition.patch | 61 ++++++++++++ .../trusted-firmware-m-corstone1000.inc | 2 + 3 files changed, 155 insertions(+) create mode 100644 meta-arm-bsp/recipes-bsp/trusted-firmware-m/files/corstone1000/0017-corstone1000-fwu-Fix-missing-destination-offset-of-p.patch create mode 100644 meta-arm-bsp/recipes-bsp/trusted-firmware-m/files/corstone1000/0018-plat-cs1k-Bound-FWU-writes-to-target-partition.patch