What is CVE-2026-7328?
CVE-2026-7328 is a missing authorization vulnerability in Caliptra Core Runtime Firmware affecting the INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, and EXTERNAL_MAILBOX_CMD commands in subsystem mode. A privileged local attacker can exploit unverified AXI addresses via mailbox commands to cause a denial of service. Applying firmware updates is recommended immediately.
Azərbaycanca: CVE-2026-7328, Caliptra Core Runtime Firmware-də tapılan missing authorization boşluğudur. Bu boşluq sistem rejimində işləyən subsystem zamanı INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA və EXTERNAL_MAILBOX_CMD əmrlərinə təsir edir. İmtiyazlı lokal hücumçu yoxlanılmamış AXI ünvanları vasitəsilə denial of service yarada bilər. Dərhal firmware yeniləmələrini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which commands in Caliptra Core Runtime Firmware are affected by CVE-2026-7328?
This vulnerability affects the INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, and EXTERNAL_MAILBOX_CMD commands while operating in subsystem mode.
What outcome can an attacker achieve by exploiting CVE-2026-7328?
A privileged local attacker can exploit unverified AXI addresses via mailbox commands to cause a denial of service.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.