PatchSiren cyber security CVE debrief
CVE-2024-13942 Rockchip CVE debrief
The Secure BootROM of RK3588s SoC is vulnerable to a time-of-check to time-of-use attack when booting from external media. This issue arises because the BootROM reads the header of the next-stage loader twice: once partially and once completely. An attacker with physical access can modify the next-stage loader data on-the-fly, potentially leading to arbitrary code execution with the highest privileges (EL3). Affected products include RK3588s: RK3588s SoC BootROM (secure) 350B20210512V100 and possibly others. Organizations should prioritize mitigation and remediation efforts, especially those with high-security requirements. The potential for arbitrary code execution with the highest privileges makes this vulnerability a high priority. Evidence from official CVE Program record and NIST NVD detail page supports the existence of this vulnerability. Limited information is available on affected scope and vendor remediation efforts.
- Vendor
- Rockchip
- Product
- RK3588s
- CVSS
- HIGH 7.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-08-31
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-08-31
Who should care
Organizations using RK3588s SoC-based devices, particularly those with high-security requirements, should prioritize mitigation and remediation efforts. This includes operators of critical infrastructure, security teams managing vulnerability programs, and platform administrators responsible for system updates and patches. The potential for arbitrary code execution with the highest privileges (EL3) makes this vulnerability a high priority for organizations with sensitive data or systems requiring robust security measures.
Technical summary
The Secure BootROM of RK3588s SoC is vulnerable to a time-of-check to time-of-use attack when booting from external media. An attacker with physical access can modify the next-stage loader data on-the-fly, potentially leading to arbitrary code execution with the highest privileges (EL3). This issue affects RK3588s: RK3588s SoC BootROM (secure) 350B20210512V100 and possibly others. The vulnerability arises from the BootROM's implementation of secure boot, which reads the header of the next-stage loader twice - once partially and once completely - allowing for a timing-based attack.
Defensive priority
High priority due to potential for arbitrary code execution with highest privileges (EL3) and availability of low-cost attack vectors.
Recommended defensive actions
- Apply mitigations per vendor instructions
- Discontinue use of the product if mitigations are unavailable
- Inventory affected systems and monitor for suspicious activity
- Implement compensating controls to limit potential damage
- Review system configurations and monitor for suspicious activity
- Track exceptions and retest remediated assets
- Verify system configurations and monitor for suspicious activity
Evidence notes
Evidence from official CVE Program record and NIST NVD detail page supports the existence of a time-of-check to time-of-use attack vulnerability in RK3588s SoC BootROM. Limited information available on affected scope and vendor remediation efforts. Defenders should verify system configurations, monitor for suspicious activity, and prioritize mitigation efforts based on system criticality and potential impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-13942 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-13942
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-13942 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-13942
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/klsecservices/Advisories/blob/master/KLSA-00230-Rockchip-RK3588s-Secure-BootROM-TOCTOU-vulnerability.md
-
Source reference
Unverified legacy reference
URL: https://www.rock-chips.com/a/en/products/RK35_Series/2022/0926/1660.html
-
Source reference
Unverified legacy reference
URL: https://www.rock-chips.com/a/en/psirt/vdp.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.