CVE-2026-11835 | Chip Alliance Core ROM up to 2.1.1 Subsystem Mode UpdateResetFlow::run toctou

SecurityVulns

A vulnerability was found in Chip Alliance Core ROM up to 2.1.1 and classified as problematic. The affected element is the function UpdateResetFlow::run of the component Subsystem Mode. Executing a manipulation can lead to time-of-check time-of-use.

This vulnerability is tracked as CVE-2026-11835. The attack is restricted to local execution. No exploit exists.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More