validate the boot image buffer across the syscall boundary
fixed in public source; rollout not reverified
details
Finding IDs
F-TREZOR-012
Status
fixed in public source; rollout not reverified
Disclosure date
Note
boot_image_check__verified applies probe_read_access to the image pointer and size in the syscall and smcall paths. This matches the reported buffer-validation gap, not F-TREZOR-008's JPEG path. A fixed firmware release and device rollout were not independently checked.
F-TREZOR-012: Memory safety. An image syscall uses insufficiently bounded memory. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Security area (1seal assessment): Authorization. Privileged image verification must validate the memory range supplied across the caller boundary. Reviewed 23 Sep 2026.
This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.