PatchSiren

Caliptra CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Caliptra CVE published 2026-07-22

CVE-2026-7328

A medium-severity vulnerability was found in Caliptra Core Runtime Firmware version 2.1.0. The issue is caused by missing authorization for INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, and EXTERNAL_MAILBOX_CMD commands in subsystem mode. This allows a privileged local attacker to cause a denial of service via mailbox commands containing unverified AXI addresses. The security impact beyond availability is i [truncated]

MEDIUM Caliptra CVE published 2026-06-24

CVE-2026-6458

A medium severity vulnerability, CVE-2026-6458, was found in Caliptra Core Firmware. The issue arises from a missing cryptographic step in the aes_256_gcm_update module, resulting in an incorrect GCM authentication tag. When the streaming AES-256-GCM API is used with empty AAD, the hardware GHASH accumulator state is not saved after the first update call, causing the final tag to exclude the first batch o [truncated]