๐Ÿ” CVE Alert

CVE-2026-7328

UNKNOWN 0.0

Unverified AXI Address in Subsystem Mode Commands Enables Denial of Service

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CMD commands) in subsystem mode allows a privileged local attacker to cause a denial of service via mailbox commands containing unverified AXI addresses. The security impact beyond availability is integration-specific. This issue affects Core Runtime Firmware: 2.1.0.

CWE CWE-862
Vendor caliptra
Product core runtime firmware
Published Jul 22, 2026
Stay Ahead of the Next One

Get instant alerts for caliptra core runtime firmware

Be the first to know when new unknown vulnerabilities affecting caliptra core runtime firmware are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Caliptra / Core Runtime Firmware
2.1.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/chipsalliance/caliptra-sw/security/advisories/GHSA-c5v4-q445-wv84