#VU82983 Missing Protection Mechanism for Alternate Hardware Interface in FreeBSD - CVE-2023-5370
Published: November 10, 2023
FreeBSD
FreeBSD Foundation
Description
The vulnerability allows a local user to compromise the affected system.
The vulnerability exists due to a missing check for CPU 0 on AArch64 hardware when deciding whether to use the Secure Monitor Call Calling Convention (SMCCC) mechanism on a given CPU. An attacker with physical access to the system can compromise the affected system.