Use of Hardware Page Aggregation (HPA) and Stage-1 and/or Stage-2 translation on Cortex-A77, Cortex-A78, Cortex-A78C, Cortex-A78AE, Cortex-A710, Cortex-X1, Cortex-X1C, Cortex-X2, Cortex-X3, Cortex-X4, Cortex-X925, Neoverse V1, Neoverse V2, Neoverse V3, Neoverse V3AE, Neoverse N2 may permit bypass of Stage-2 translation and/or GPT protection.
References
| Link | Resource |
|---|---|
| https://developer.arm.com/Arm%20Security%20Center/Arm%20CPU%20Vulnerability%20CVE-2024-5660 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
Configuration 7 (hide)
| AND |
|
Configuration 8 (hide)
| AND |
|
Configuration 9 (hide)
| AND |
|
Configuration 10 (hide)
| AND |
|
Configuration 11 (hide)
| AND |
|
Configuration 12 (hide)
| AND |
|
Configuration 13 (hide)
| AND |
|
Configuration 14 (hide)
| AND |
|
Configuration 15 (hide)
| AND |
|
Configuration 16 (hide)
| AND |
|
History
05 Jan 2026, 14:44
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://developer.arm.com/Arm%20Security%20Center/Arm%20CPU%20Vulnerability%20CVE-2024-5660 - Vendor Advisory | |
| First Time |
Arm cortex-a78c
Arm neoverse-v3 Arm cortex-x2 Arm cortex-x4 Firmware Arm cortex-x3 Arm cortex-x2 Firmware Arm neoverse-v3 Firmware Arm cortex-x1c Firmware Arm cortex-x1 Arm cortex-x925 Firmware Arm neoverse N2 Arm cortex-x1c Arm cortex-x4 Arm cortex-a78c Firmware Arm neoverse-v3ae Firmware Arm cortex-a78 Firmware Arm cortex-a78ae Arm cortex-x1 Firmware Arm cortex-a77 Firmware Arm neoverse N2 Firmware Arm cortex-a710 Arm neoverse-v1 Arm neoverse-v2 Arm cortex-a78 Arm cortex-x3 Firmware Arm neoverse-v3ae Arm neoverse-v1 Firmware Arm Arm cortex-a710 Firmware Arm cortex-a77 Arm neoverse-v2 Firmware Arm cortex-x925 Arm cortex-a78ae Firmware |
|
| CPE | cpe:2.3:o:arm:neoverse-v1_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:arm:cortex-x3:-:*:*:*:*:*:*:* cpe:2.3:h:arm:cortex-x1c:-:*:*:*:*:*:*:* cpe:2.3:o:arm:cortex-a78c_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:arm:neoverse-v2:-:*:*:*:*:*:*:* cpe:2.3:o:arm:cortex-x3_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:arm:neoverse-v3:-:*:*:*:*:*:*:* cpe:2.3:o:arm:neoverse-v2_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:arm:cortex-a710_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:arm:cortex-x1c_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:arm:cortex-x2_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:arm:cortex-x1_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:arm:neoverse-v3ae_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:arm:neoverse_n2_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:arm:cortex-a78c:-:*:*:*:*:*:*:* cpe:2.3:h:arm:cortex-x1:-:*:*:*:*:*:*:* cpe:2.3:h:arm:cortex-a78:-:*:*:*:*:*:*:* cpe:2.3:o:arm:cortex-a78_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:arm:cortex-a78ae_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:arm:cortex-a78ae:-:*:*:*:*:*:*:* cpe:2.3:o:arm:cortex-a77_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:arm:cortex-a710:-:*:*:*:*:*:*:* cpe:2.3:o:arm:cortex-x4_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:arm:cortex-a77:-:*:*:*:*:*:*:* cpe:2.3:h:arm:cortex-x4:-:*:*:*:*:*:*:* cpe:2.3:o:arm:cortex-x925_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:arm:cortex-x2:-:*:*:*:*:*:*:* cpe:2.3:h:arm:cortex-x925:-:*:*:*:*:*:*:* cpe:2.3:h:arm:neoverse_n2:-:*:*:*:*:*:*:* cpe:2.3:h:arm:neoverse-v3ae:-:*:*:*:*:*:*:* cpe:2.3:o:arm:neoverse-v3_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:arm:neoverse-v1:-:*:*:*:*:*:*:* |
16 Dec 2024, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| Summary | (en) Use of Hardware Page Aggregation (HPA) and Stage-1 and/or Stage-2 translation on Cortex-A77, Cortex-A78, Cortex-A78C, Cortex-A78AE, Cortex-A710, Cortex-X1, Cortex-X1C, Cortex-X2, Cortex-X3, Cortex-X4, Cortex-X925, Neoverse V1, Neoverse V2, Neoverse V3, Neoverse V3AE, Neoverse N2 may permit bypass of Stage-2 translation and/or GPT protection. |
10 Dec 2024, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
10 Dec 2024, 14:30
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-12-10 14:30
Updated : 2026-01-05 14:44
NVD link : CVE-2024-5660
Mitre link : CVE-2024-5660
CVE.ORG link : CVE-2024-5660
JSON object : View
Products Affected
arm
- cortex-a710
- cortex-a78c
- cortex-x4_firmware
- neoverse-v3ae_firmware
- cortex-a78ae_firmware
- neoverse-v1_firmware
- cortex-x1c_firmware
- neoverse_n2
- cortex-x1_firmware
- cortex-a710_firmware
- cortex-a78
- cortex-a78ae
- cortex-x3_firmware
- neoverse_n2_firmware
- neoverse-v1
- neoverse-v3
- cortex-x2_firmware
- cortex-x1c
- cortex-x4
- cortex-x3
- cortex-a77_firmware
- neoverse-v2_firmware
- neoverse-v3_firmware
- cortex-x925
- cortex-a77
- cortex-x925_firmware
- cortex-x2
- neoverse-v3ae
- cortex-a78c_firmware
- cortex-x1
- cortex-a78_firmware
- neoverse-v2
CWE
CWE-668
Exposure of Resource to Wrong Sphere
