When using Arm Cortex-M Security Extensions (CMSE), Secure stack
contents can be leaked to Non-secure state via floating-point registers
when a Secure to Non-secure function call is made that returns a
floating-point value and when this is the first use of floating-point
since entering Secure state. This allows an attacker to read a limited
quantity of Secure stack contents with an impact on confidentiality.
This issue is specific to code generated using LLVM-based compilers.
Metrics
Affected Vendors & Products
References
History
Fri, 01 Nov 2024 02:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Thu, 31 Oct 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 31 Oct 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | When using Arm Cortex-M Security Extensions (CMSE), Secure stack contents can be leaked to Non-secure state via floating-point registers when a Secure to Non-secure function call is made that returns a floating-point value and when this is the first use of floating-point since entering Secure state. This allows an attacker to read a limited quantity of Secure stack contents with an impact on confidentiality. This issue is specific to code generated using LLVM-based compilers. | |
Title | CMSE secure state may leak from stack to floating-point registers | |
Weaknesses | CWE-226 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Arm
Published: 2024-10-31T17:01:49.725Z
Updated: 2024-10-31T17:53:36.751Z
Reserved: 2024-08-16T15:09:09.866Z
Link: CVE-2024-7883
Vulnrichment
Updated: 2024-10-31T17:53:22.080Z
NVD
Status : Awaiting Analysis
Published: 2024-10-31T17:15:14.013
Modified: 2024-11-01T12:57:03.417
Link: CVE-2024-7883
Redhat