A medium-severity vulnerability was found in Caliptra Core Runtime Firmware version 2.1.0. The issue is caused by missing authorization for INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, and EXTERNAL_MAILBOX_CMD commands in subsystem mode. This allows a privileged local attacker to cause a denial of service via mailbox commands containing unverified AXI addresses. The security impact beyond availability is i [truncated]
A medium severity vulnerability, CVE-2026-6458, was found in Caliptra Core Firmware. The issue arises from a missing cryptographic step in the aes_256_gcm_update module, resulting in an incorrect GCM authentication tag. When the streaming AES-256-GCM API is used with empty AAD, the hardware GHASH accumulator state is not saved after the first update call, causing the final tag to exclude the first batch o [truncated]