AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 59 Bitcoin

Merge pull request #680 from Foundation-Devices/SFT-7355-harden-firmware-header-check

Public commit record

What the developer wrote

Authored by mjg-foundation

58/100 · Thin
Merge pull request #680 from Foundation-Devices/SFT-7355-harden-firmware-header-check

SFT-7355: harden firmware header check
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
The short version

What changed, and why it matters

This commit hardens how the Passport hardware wallet checks firmware update headers. It makes sure developer/user-signed firmware cannot carry a second public-key index or a second signature, and it prevents a 'time-of-check/time-of-use' race where the firmware file on the microSD card could be swapped after the user reviewed it but before it is copied to flash. The change is defensive: it closes a class of bugs where a partly trusted or attacker-modified header might be accepted, but there is no direct evidence in the commit that an actual exploit exists in the wild.

Recommended action

Treat this as a legitimate hardening fix. Users should install the resulting firmware once it is released, and the vendor should consider whether the previous behavior (ignored second key/signature on developer images, and re-read headers during update) warrants a security advisory or CVE. Reviewers should verify that the cached header cannot be modified by untrusted code after it is set in update_firmware_flow.py.

Security signals we found

01

New validation requiring zeroed second key/signature for user-signed firmware

02

TOCTOU mitigation: cached header compared against re-read file header before signature verification and before staging to SPI flash

03

Staging of validated header from memory rather than re-reading from untrusted storage

04

Consistent use of a single classification helper (firmware_is_user_signed) across bootloader and application code

05

Addition of Rust unit tests and Python host tests for header mutation, truncation, and second-key/signature handling

Risk score

Why this scored 59/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 8/15
Affected reach 10/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.