An unprivileged context can trigger a data
memory-dependent prefetch engine to fetch the contents of a privileged location
and consume those contents as an address that is also dereferenced.
References
| Link | Resource |
|---|---|
| https://developer.arm.com/Arm%20Security%20Center/Arm%20CPU%20Vulnerability%20CVE-2024-7881 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
Configuration 7 (hide)
| AND |
|
Configuration 8 (hide)
| AND |
|
Configuration 9 (hide)
| AND |
|
History
18 Dec 2025, 15:36
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-203 | |
| First Time |
Arm c1-pro Firmware
Arm neoverse-v2 Arm neoverse-v3 Arm cortex-x4 Firmware Arm cortex-x3 Arm c1-pro Arm c1-ultra Firmware Arm cortex-x3 Firmware Arm c1-premium Arm neoverse-v3 Firmware Arm neoverse-v3ae Arm Arm cortex-x925 Firmware Arm c1-ultra Arm cortex-x4 Arm neoverse-v3ae Firmware Arm c1-premium Firmware Arm neoverse-v2 Firmware Arm cortex-x925 |
|
| CPE | cpe:2.3:h:arm:cortex-x3:-:*:*:*:*:*:*:* cpe:2.3:o:arm:c1-premium_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:arm:neoverse-v2:-:*:*:*:*:*:*:* cpe:2.3:h:arm:neoverse-v3:-:*:*:*:*:*:*:* cpe:2.3:o:arm:cortex-x3_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:arm:cortex-x4_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:arm:neoverse-v2_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:arm:cortex-x4:-:*:*:*:*:*:*:* cpe:2.3:h:arm:c1-ultra:-:*:*:*:*:*:*:* cpe:2.3:o:arm:cortex-x925_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:arm:cortex-x925:-:*:*:*:*:*:*:* cpe:2.3:h:arm:c1-pro:-:*:*:*:*:*:*:* cpe:2.3:h:arm:neoverse-v3ae:-:*:*:*:*:*:*:* cpe:2.3:o:arm:neoverse-v3ae_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:arm:c1-pro_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:arm:neoverse-v3_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:arm:c1-premium:-:*:*:*:*:*:*:* cpe:2.3:o:arm:c1-ultra_firmware:-:*:*:*:*:*:*:* |
|
| References | () https://developer.arm.com/Arm%20Security%20Center/Arm%20CPU%20Vulnerability%20CVE-2024-7881 - Vendor Advisory |
06 Feb 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.1 |
28 Jan 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-01-28 15:15
Updated : 2025-12-18 15:36
NVD link : CVE-2024-7881
Mitre link : CVE-2024-7881
CVE.ORG link : CVE-2024-7881
JSON object : View
Products Affected
arm
- c1-pro_firmware
- neoverse-v3_firmware
- cortex-x3_firmware
- c1-ultra_firmware
- cortex-x925
- c1-ultra
- neoverse-v2
- cortex-x925_firmware
- c1-pro
- neoverse-v3ae
- cortex-x4_firmware
- neoverse-v3
- neoverse-v3ae_firmware
- cortex-x4
- c1-premium
- neoverse-v2_firmware
- cortex-x3
- c1-premium_firmware
CWE
CWE-203
Observable Discrepancy
