#ZynqMP
Ah ouais, ça déconne pas...
78 sous-systèmes atteints :-/
ubuntu.com/security/not...
USN-7166-4: Linux kernel (Xilinx ZynqMP) vulnerabilities | Ubuntu security notices | Ubuntu
Ubuntu is an open source software operating system that runs from the desktop, to the cloud, to all your internet connected things.
ubuntu.com
January 25, 2025 at 1:21 PM
c'est quoi un "Xilinx ZynqMP"
et ça se pronnonce comment ? 🤣
January 25, 2025 at 1:31 PM
New Linux kernel advisory drops: Xilinx ZynqMP DMA memory corruption (CVE-2024-7608) threatens industrial IoT. Deep dive explains patching + eBPF containment strategies. Read more:👉 tinyurl.com/3k9jf5fc #IoTsecurity #Linux
Critical Linux Kernel Vulnerability in Ubuntu: CVE-2024-7608 (Xilinx ZynqMP Patch Analysis)
Blog com notícias sobre, Linux, Android, Segurança , etc
tinyurl.com
July 13, 2025 at 7:18 PM
USN-7390-1: Linux kernel (Xilinx ZynqMP) vulnerabilities

https://ubuntu.com/security/notices/USN-7390-1

Attila Szász discovered that the HFS+ file system implementation in the
Linux Kernel contained a heap overflow vulnerability. An attacker could use
a specially crafted file system image that, …
USN-7390-1: Linux kernel (Xilinx ZynqMP) vulnerabilities | Ubuntu security notices | Ubuntu
Ubuntu is an open source software operating system that runs from the desktop, to the cloud, to all your internet connected things.
ubuntu.com
March 28, 2025 at 3:00 PM
AMD's open-source AMDGPU driver skips HDMI 2.1 on Radeon due to HDMI Forum licensing. Xilinx drivers for ZynqMP/Versal SoCs manage partial support via firmware tweaks. Hardware differences opening paths around GPU roadblocks. Linux folks eyeing fixes. #OpenSource #Linux
November 25, 2025 at 9:45 PM
Time to play: spot the Python mistake causing mysterious build failures! This one’s a fun one. github.com/Xilinx/meta-...
meta-xilinx-tools/classes-recipe/dfx_dtg_full_common.bbclass at master · Xilinx/meta-xilinx-tools
Yocto Project layer enables AMD Xilinx tools related metadata for MicroBlaze, Zynq, ZynqMP and Versal devices. - Xilinx/meta-xilinx-tools
github.com
April 30, 2025 at 2:40 PM
Building safety- or security-critical systems?
wolfBoot now replaces the Xilinx ZynqMP FSBL with a single, auditable secure boot stage—helping reduce certification complexity while supporting TPM-measured boot, FIPS-ready crypto, and post-quantum algorithms.
August 6, 2026 at 12:23 AM
🚨 EUVD-2025-209749
📊 7.8/10
🏢 Linux

📝 In the Linux kernel, the following vulnerability has been resolved:

Revert "arm64: zynqmp: Add an OP-TEE node to the device tree"

This reverts commit 06...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-209749

#cybersecurity #infosec #cve #euvd
July 30, 2026 at 7:01 AM
wolfBoot as the Xilinx ZynqMP FSBL: a full-featured secure first-stage replacement
wolfBoot as the Xilinx ZynqMP FSBL: a full-featured secure first-stage replacement
wolfBoot can now run as the First Stage Boot Loader (FSBL) on Xilinx ZynqMP, replacing the stock Xilinx FSBL entirely. On a ZCU102 (xczu9eg) the BootROM hands control straight to wolfBoot in on-chip memory (OCM) at EL3; wolfBoot brings up the processing system, verifies a signed image with its own keys, and boots Linux to a login prompt – validated end-to-end on real hardware. This moves your key-based verification to the earliest software stage the SoC runs, and it is a full-featured replacement: signed, compressed FIT images, direct programmable-logic loading, a silicon-anchored root of trust, and measured boot. How it boots The stock Xilinx chain runs the FSBL, PMU firmware, ARM Trusted Firmware (BL31), and U-Boot before Linux. As the FSBL, wolfBoot collapses that to one init-and-verify stage that hands straight to BL31 and on to Linux: In that single stage wolfBoot runs psu_init() (PLLs, DDR, MIO, clocks, optional PS-GTR serdes), authenticates a wolfBoot-signed FIT carrying the kernel, BL31, and device tree (with optional compression), optionally programs an FPGA bitstream from that same signed FIT into the programmable logic, loads the PMU configuration, then hands off to BL31 – upstream Xilinx ARM Trusted Firmware plus a small device-tree-forwarding patch – which drops the kernel to a lower exception level. Removing the separate FSBL load and the U-Boot stage, and verifying the image once, should also reduce time-to-Linux; formal boot-time metrics are being collected for a follow-up. Hardware root of trust at EL3 At EL3 with no firmware beneath it, wolfBoot drives the ZynqMP Crypto/Security Unit (CSU) engines directly: a read-only eFuse dump (security bits, PPK hash, PUF fields), PUF-derived device KEK regeneration, and hardware AES-256-GCM with the tag enforced. The same CSU driver tree is dual-mode – direct MMIO as the FSBL, secure-monitor calls as a normal-world image. Enabling Xilinx eFuse PPK RSA authentication anchors wolfBoot’s own image to a key hash burned into the device. Algorithms and encryption Purpose Options Config tokens Signature – classic RSA-2048 / 3072 / 4096 (PKCS#1 v1.5 and PSS), ECDSA P-256 / P-384 / P-521, Ed25519, Ed448 SIGN=RSA4096 / ECC384 / ED25519 … Signature – post-quantum LMS/HSS, XMSS/XMSS^MT (stateful hash-based), ML-DSA / Dilithium L2/L3/L5 (lattice) SIGN=LMS / XMSS / ML_DSA Signature – hybrid Any classic + any PQ (e.g. ML-DSA-65 + ECDSA P-384) – two independent signatures over one image SIGN=ML_DSA + SIGN_SECONDARY=ECC384 + WOLFBOOT_UNIVERSAL_KEYSTORE=1 Hash SHA-256, SHA-384, SHA3-384 HASH=SHA3 on ZynqMP (hardware CSU SHA3) Update-image encryption AES-128-CTR, AES-256-CTR, ChaCha20; key can live in a TPM/HSM ENCRYPT=1 (+ENCRYPT_WITH_AES256=1) Hardware AES (CSU) AES-256-GCM via the ZynqMP CSU engine (KUP / device key), tag enforced ZYNQMP_SEC=1 The ZynqMP FSBL example ships with RSA-4096 + SHA3-384; the same tree builds any of the above, including a quantum-resistant or hybrid configuration for long-lived deployments. Measured boot with a TPM wolfBoot uses wolfTPM to extend PCRs with measurements of everything it loads, for an attestable TPM 2.0 record of the boot. Supply the TPM three ways: a firmware TPM in ARM TrustZone, a firmware TPM on a MicroBlaze-V (RISC-V) soft core in the PL, or an external physical TPM 2.0 over SPI. Both firmware-TPM paths are supported, with working reference examples you can build from. Safety-critical certification For programs pursuing DO-178C (up to DAL A), IEC 61508, or ISO 26262, collapsing the trusted boot chain to one auditable, open-source stage you build, sign, and certify yourself – portable C, FIPS 140-3-capable crypto, fewer independent binaries in the critical path – means a smaller certification surface. Try it cp config/examples/zynqmp_fsbl.config .config make ZYNQMP_FSBL=1 ZYNQMP_PSU_INIT_DIR=/path/to/board The board-specific psu_init_gpl.c (Xilinx-tool-generated DDR/clock data for your board) is supplied at build time and is not in the tree. QSPI and SD-card boot are both supported; docs/Targets.md has the full walkthrough – building BL31, packaging BOOT.BIN with bootgen, boot-mode switches, and the FIT layout. Full implementation: wolfBoot PR #817. If you have questions about any of the above, please contact us at facts@wolfssl.com or call us at +1 425 245 8247. Download wolfSSL Now
dlvr.it
July 17, 2026 at 3:06 PM
> USN-8528-1: Linux kernel (Xilinx ZynqMP) vulnerabilities
https://ubuntu.com/security/notices/USN-8528-1
USN-8528-1: Linux kernel (Xilinx ZynqMP) vulnerabilities
It was discovered that the Linux kernel algif_aead module did not properly handle in-place cryptographic operations. This flaw is known as Copy Fail. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-31431) It was discovered that the Linux kernel did not properly handle shared page fragments during socket buffer operations, collectively known as Dirty Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the RxRPC networking subsystem when processing paged fragments. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43284, CVE-2026-43500) It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503, CVE-2026-46300) Qualys discovered that a race condition existed in the ptrace subsystem of the Linux kernel when privileged processes are exiting. An unprivileged local attacker could use this issue to expose sensitive information. (CVE-2026-46333) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - RISC-V architecture; - Cryptographic API; - InfiniBand drivers; - IOMMU subsystem; - Ethernet bonding driver; - Network drivers; - STMicroelectronics network drivers; - NVME drivers; - x86 platform drivers; - SCSI subsystem; - SPI subsystem; - TCM subsystem; - USB over IP driver; - File systems infrastructure; - HFS+ file system; - Network file system (NFS) server daemon; - SMB network file system; - IPv6 networking; - Netfilter; - Tracing infrastructure; - io_uring subsystem; - Timer subsystem; - B.A.T.M.A.N. meshing protocol; - Bluetooth subsystem; - Ethernet bridge; - Ceph Core library; - IPv4 networking; - MAC80211 subsystem; - Multipath TCP; - Packet sockets; - RDS protocol; - RxRPC session sockets; - SMC sockets; - Sun RPC protocol; - TLS protocol; - X.25 network layer; - AMD SoC Alsa drivers; - KVM subsystem; (CVE-2022-48816, CVE-2023-53673, CVE-2024-35862, CVE-2024-50060, CVE-2025-37778, CVE-2025-37822, CVE-2025-37924, CVE-2025-38201, CVE-2025-40082, CVE-2025-68214, CVE-2025-68263, CVE-2025-71089, CVE-2025-71220, CVE-2025-71222, CVE-2025-71224, CVE-2026-23176, CVE-2026-23180, CVE-2026-23182, CVE-2026-23190, CVE-2026-23193, CVE-2026-23198, CVE-2026-23202, CVE-2026-23206, CVE-2026-23216, CVE-2026-23256, CVE-2026-23257, CVE-2026-23258, CVE-2026-23262, CVE-2026-23272, CVE-2026-23274, CVE-2026-23278, CVE-2026-23351, CVE-2026-23428, CVE-2026-23450, CVE-2026-23455, CVE-2026-31402, CVE-2026-31418, CVE-2026-31419, CVE-2026-31478, CVE-2026-31504, CVE-2026-31533, CVE-2026-31607, CVE-2026-31637, CVE-2026-31649, CVE-2026-31657, CVE-2026-31659, CVE-2026-31668, CVE-2026-31669, CVE-2026-31682, CVE-2026-31685, CVE-2026-43011, CVE-2026-43033, CVE-2026-43037, CVE-2026-43038, CVE-2026-43071, CVE-2026-43077, CVE-2026-43078, CVE-2026-43114, CVE-2026-43117, CVE-2026-43186, CVE-2026-43304, CVE-2026-43341, CVE-2026-43383, CVE-2026-43406, CVE-2026-43407, CVE-2026-43414, CVE-2026-43493, CVE-2026-43494, CVE-2026-43501, CVE-2026-45988, CVE-2026-46028, CVE-2026-46043, CVE-2026-46119, CVE-2026-46135, CVE-2026-46195, CVE-2026-46243)
ubuntu.com
July 10, 2026 at 3:40 PM
This webinar shows wolfTPM fTPM 2.0 in action with SPDM integration and Post-Quantum Cryptography (ML-DSA, ML-KEM), plus real-world demos on #STM32H5, RISC-V PolarFire SoC, and ZynqMP platforms.
July 5, 2026 at 4:08 PM
ZynqMP에 u-boot와 리눅스 올리기 할만할까요? 까짓거 한번 해보죠
January 27, 2026 at 2:05 PM
> USN-7654-5: Linux kernel (Xilinx ZynqMP) vulnerabilities
https://ubuntu.com/security/notices/USN-7654-5
USN-7654-5: Linux kernel (Xilinx ZynqMP) vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - PA-RISC architecture; - PowerPC architecture; - x86 architecture; - Block layer subsystem; - Cryptographic API; - Serial ATA and Parallel ATA drivers; - Bluetooth drivers; - Bus devices; - CPU frequency scaling framework; - Buffer Sharing and Synchronization framework; - DMA engine subsystem; - ARM SCMI message protocol; - GPU drivers; - HID subsystem; - HSI subsystem; - I2C subsystem; - I3C subsystem; - IIO subsystem; - InfiniBand drivers; - IOMMU subsystem; - IRQ chip drivers; - MCB driver; - Multiple devices driver; - Media drivers; - Multifunction device drivers; - PCI Endpoint Test driver; - MTD block device drivers; - Network drivers; - Device tree and open firmware driver; - PCI subsystem; - TI SCI PM domains driver; - PWM drivers; - S/390 drivers; - SCSI subsystem; - Samsung SoC drivers; - TCM subsystem; - UFS subsystem; - Cadence USB3 driver; - ChipIdea USB driver; - USB Device Class drivers; - DesignWare USB3 driver; - USB Gadget drivers; - USB Type-C support driver; - USB Type-C Connector System Software Interface driver; - Backlight driver; - Framebuffer layer; - Xen hypervisor drivers; - BTRFS file system; - Ext4 file system; - F2FS file system; - File systems infrastructure; - JFS file system; - Network file system (NFS) client; - Network file system (NFS) server daemon; - Proc file system; - SMB network file system; - Kernel stack handling interfaces; - Bluetooth subsystem; - Network traffic control; - SCTP protocol; - BPF subsystem; - Kernel command line parsing driver; - Tracing infrastructure; - Memory management; - 802.1Q VLAN protocol; - Networking core; - IPv6 networking; - MAC80211 subsystem; - Management Component Transport Protocol (MCTP); - Multipath TCP; - Netfilter; - Open vSwitch; - Phonet protocol; - TIPC protocol; - TLS protocol; - Virtio sound driver; - CPU Power monitoring subsystem; (CVE-2025-37758, CVE-2025-37983, CVE-2025-37768, CVE-2025-37810, CVE-2025-23140, CVE-2025-37757, CVE-2024-35943, CVE-2022-49168, CVE-2024-54458, CVE-2024-56751, CVE-2025-37985, CVE-2025-37969, CVE-2025-37930, CVE-2025-38094, CVE-2025-37749, CVE-2025-37796, CVE-2024-46751, CVE-2025-37780, CVE-2025-37738, CVE-2025-37765, CVE-2024-35866, CVE-2025-37771, CVE-2025-37892, CVE-2024-50280, CVE-2025-37789, CVE-2025-21839, CVE-2023-52757, CVE-2025-37781, CVE-2025-38024, CVE-2024-50258, CVE-2023-52572, CVE-2025-23148, CVE-2024-27402, CVE-2025-37824, CVE-2025-37875, CVE-2025-37940, CVE-2025-37998, CVE-2025-37883, CVE-2024-26739, CVE-2025-37858, CVE-2024-53203, CVE-2025-37970, CVE-2025-23150, CVE-2025-23163, CVE-2025-23144, CVE-2025-38023, CVE-2025-37773, CVE-2025-37811, CVE-2025-37792, CVE-2025-37739, CVE-2025-37991, CVE-2025-37836, CVE-2025-37812, CVE-2022-49535, CVE-2025-37927, CVE-2025-37885, CVE-2025-23142, CVE-2025-23161, CVE-2024-53128, CVE-2025-37850, CVE-2025-37857, CVE-2025-37992, CVE-2025-37790, CVE-2024-49960, CVE-2025-37756, CVE-2025-37808, CVE-2025-37905, CVE-2024-50272, CVE-2025-37742, CVE-2025-37967, CVE-2025-37994, CVE-2024-42322, CVE-2025-37794, CVE-2025-37949, CVE-2025-37787, CVE-2025-37995, CVE-2024-35790, CVE-2024-46816, CVE-2024-46742, CVE-2025-23159, CVE-2022-49063, CVE-2025-37788, CVE-2025-37797, CVE-2025-37913, CVE-2025-37740, CVE-2025-37989, CVE-2025-37914, CVE-2025-23151, CVE-2022-48893, CVE-2025-37851, CVE-2025-23157, CVE-2025-37923, CVE-2025-23158, CVE-2025-37871, CVE-2025-37982, CVE-2025-37862, CVE-2022-21546, CVE-2025-37841, CVE-2025-37844, CVE-2024-35867, CVE-2025-23147, CVE-2025-37819, CVE-2024-49989, CVE-2025-37830, CVE-2025-38009, CVE-2024-46774, CVE-2025-37990, CVE-2025-37859, CVE-2025-37911, CVE-2024-38540, CVE-2025-37767, CVE-2025-37770, CVE-2025-22062, CVE-2025-37840, CVE-2025-23156, CVE-2025-23145, CVE-2025-37839, CVE-2025-37823, CVE-2025-22027, CVE-2025-37838, CVE-2025-37805, CVE-2025-37964, CVE-2025-37867, CVE-2025-37915, CVE-2025-38005, CVE-2025-37829, CVE-2025-37909, CVE-2025-37741, CVE-2024-26686, CVE-2024-50125, CVE-2024-38541, CVE-2025-37803, CVE-2025-23146, CVE-2025-37881, CVE-2025-37766, CVE-2025-37912, CVE-2024-36908, CVE-2025-21853, CVE-2025-37817)
ubuntu.com
July 29, 2025 at 3:40 PM