PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-13942 Rockchip CVE debrief

The Secure BootROM of RK3588s SoC is vulnerable to a time-of-check to time-of-use attack when booting from external media. This issue arises because the BootROM reads the header of the next-stage loader twice: once partially and once completely. An attacker with physical access can modify the next-stage loader data on-the-fly, potentially leading to arbitrary code execution with the highest privileges (EL3). Affected products include RK3588s: RK3588s SoC BootROM (secure) 350B20210512V100 and possibly others. Organizations should prioritize mitigation and remediation efforts, especially those with high-security requirements. The potential for arbitrary code execution with the highest privileges makes this vulnerability a high priority. Evidence from official CVE Program record and NIST NVD detail page supports the existence of this vulnerability. Limited information is available on affected scope and vendor remediation efforts.

Vendor
Rockchip
Product
RK3588s
CVSS
HIGH 7.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-19
Original CVE updated
2026-08-31
Advisory published
2026-08-19
Advisory updated
2026-08-31

Who should care

Organizations using RK3588s SoC-based devices, particularly those with high-security requirements, should prioritize mitigation and remediation efforts. This includes operators of critical infrastructure, security teams managing vulnerability programs, and platform administrators responsible for system updates and patches. The potential for arbitrary code execution with the highest privileges (EL3) makes this vulnerability a high priority for organizations with sensitive data or systems requiring robust security measures.

Technical summary

The Secure BootROM of RK3588s SoC is vulnerable to a time-of-check to time-of-use attack when booting from external media. An attacker with physical access can modify the next-stage loader data on-the-fly, potentially leading to arbitrary code execution with the highest privileges (EL3). This issue affects RK3588s: RK3588s SoC BootROM (secure) 350B20210512V100 and possibly others. The vulnerability arises from the BootROM's implementation of secure boot, which reads the header of the next-stage loader twice - once partially and once completely - allowing for a timing-based attack.

Defensive priority

High priority due to potential for arbitrary code execution with highest privileges (EL3) and availability of low-cost attack vectors.

Recommended defensive actions

  • Apply mitigations per vendor instructions
  • Discontinue use of the product if mitigations are unavailable
  • Inventory affected systems and monitor for suspicious activity
  • Implement compensating controls to limit potential damage
  • Review system configurations and monitor for suspicious activity
  • Track exceptions and retest remediated assets
  • Verify system configurations and monitor for suspicious activity

Evidence notes

Evidence from official CVE Program record and NIST NVD detail page supports the existence of a time-of-check to time-of-use attack vulnerability in RK3588s SoC BootROM. Limited information available on affected scope and vendor remediation efforts. Defenders should verify system configurations, monitor for suspicious activity, and prioritize mitigation efforts based on system criticality and potential impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-13942 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-13942

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-13942 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-13942

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.