CVE-2024-7883

When using Arm Cortex-M Security Extensions (CMSE), Secure stack contents can be leaked to Non-secure state via floating-point registers when a Secure to Non-secure function call is made that returns a floating-point value and when this is the first use of floating-point since entering Secure state. This allows an attacker to read a limited quantity of Secure stack contents with an impact on confidentiality. This issue is specific to code generated using LLVM-based compilers.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:arm:arm_compiler_for_embedded:*:*:*:*:*:*:*:*
cpe:2.3:a:arm:arm_compiler_for_embedded_fusa:6.16:*:*:*:lts:*:*:*
cpe:2.3:a:arm:arm_compiler_for_embedded_fusa:6.21:*:*:*:lts:*:*:*
cpe:2.3:a:arm:arm_compiler_for_functional_safety:6.6:*:*:*:*:*:*:*
cpe:2.3:a:arm:clang:*:*:*:*:*:*:*:*

History

23 Dec 2025, 15:30

Type Values Removed Values Added
First Time Arm
Arm arm Compiler For Functional Safety
Arm clang
Arm arm Compiler For Embedded Fusa
Arm arm Compiler For Embedded
Summary
  • (es) Al utilizar las extensiones de seguridad Arm Cortex-M (CMSE), el contenido de la pila segura puede filtrarse al estado no seguro a través de registros de punto flotante cuando se realiza una llamada de función de seguro a no seguro que devuelve un valor de punto flotante y cuando este es el primer uso del punto flotante desde que se ingresa al estado seguro. Esto permite que un atacante lea una cantidad limitada de contenido de la pila segura con un impacto en la confidencialidad. Este problema es específico del código generado mediante compiladores basados ??en LLVM.
CPE cpe:2.3:a:arm:arm_compiler_for_functional_safety:6.6:*:*:*:*:*:*:*
cpe:2.3:a:arm:arm_compiler_for_embedded_fusa:6.21:*:*:*:lts:*:*:*
cpe:2.3:a:arm:arm_compiler_for_embedded:*:*:*:*:*:*:*:*
cpe:2.3:a:arm:clang:*:*:*:*:*:*:*:*
cpe:2.3:a:arm:arm_compiler_for_embedded_fusa:6.16:*:*:*:lts:*:*:*
References () https://developer.arm.com/Arm%20Security%20Center/Cortex-M%20Security%20Extensions%20Vulnerability - () https://developer.arm.com/Arm%20Security%20Center/Cortex-M%20Security%20Extensions%20Vulnerability - Vendor Advisory, Exploit

31 Oct 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-31 17:15

Updated : 2025-12-23 15:30


NVD link : CVE-2024-7883

Mitre link : CVE-2024-7883

CVE.ORG link : CVE-2024-7883


JSON object : View

Products Affected

arm

  • arm_compiler_for_embedded_fusa
  • clang
  • arm_compiler_for_functional_safety
  • arm_compiler_for_embedded
CWE
CWE-226

Sensitive Information in Resource Not Removed Before Reuse