Trusted Firmware M 1.4.x through 1.4.1 has a buffer overflow issue in the Firmware Update partition. In the IPC model, a psa_fwu_write caller from SPE or NSPE can overwrite stack memory locations.
https://www.trustedfirmware.org
https://git.trustedfirmware.org/TF-M/trusted-firmware-m.git/