CRITICAL🇵🇱 Wersja polska

CVE-2024-5660

CVSS 9.8v3.1pub. 2024-12-10upd. 2026-01-05

Use of Hardware Page Aggregation (HPA) and Stage-1 and/or Stage-2 translation on Cortex-A77, Cortex-A78, Cortex-A78C, Cortex-A78AE, Cortex-A710, Cortex-X1, Cortex-X1C, Cortex-X2, Cortex-X3, Cortex-X4, Cortex-X925, Neoverse V1, Neoverse V2, Neoverse V3, Neoverse V3AE, Neoverse N2 may permit bypass of Stage-2 translation and/or GPT protection.

🤖 AI Analysis
How it works

The Hardware Page Aggregation (HPA) mechanism is used to combine multiple small memory pages into larger blocks to optimize address translation performance. When combined with Stage-1 and/or Stage-2 translation, applied in virtualized environments to isolate guest memory from the host, HPA can be exploited in a way that bypasses Stage-2 verification or GPT protection. Granule Protection Table (GPT) is a mechanism protecting specific memory areas from access at lower privilege levels, such as the normal world of the operating system. Improper interaction of HPA with these translation mechanisms allows access to memory areas that should be protected.

Impact

An attacker can gain unauthorized access to protected memory areas, potentially compromising the confidentiality, integrity, and availability of data, including data processed by the hypervisor or Trusted Execution Environment (TEE). This could lead to breaking virtual machine isolation or bypassing system security mechanisms.

Mitigation & patch

Apply patches available from the manufacturer according to references published by Arm Security Center at https://developer.arm.com/Arm%20Security%20Center/Arm%20CPU%20Vulnerability%20CVE-2024-5660. OEM device manufacturers based on the mentioned cores should provide appropriate firmware updates. Monitor security communications from operating system vendors and virtualization platform providers utilizing these processors.

Who is affected

Arm processors: Cortex-A77, Cortex-A78, Cortex-A78C, Cortex-A78AE, Cortex-A710, Cortex-X1, Cortex-X1C, Cortex-X2, Cortex-X3, Cortex-X4, Cortex-X925, Neoverse V1, Neoverse V2, Neoverse V3, Neoverse V3AE, Neoverse N2 — specific firmware versions indicated in manufacturer references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Arm Cortex A710

    HW
    Arm
    all versions
  • Arm Cortex A710 Firmware

    OS
    Arm
    all versions
  • Arm Cortex A77

    HW
    Arm
    all versions
  • Arm Cortex A77 Firmware

    OS
    Arm
    all versions
  • Arm Cortex A78

    HW
    Arm
    all versions
  • Arm Cortex A78ae

    HW
    Arm
    all versions
  • Arm Cortex A78ae Firmware

    OS
    Arm
    all versions
  • Arm Cortex A78c

    HW
    Arm
    all versions
  • Arm Cortex A78c Firmware

    OS
    Arm
    all versions
  • Arm Cortex A78 Firmware

    OS
    Arm
    all versions
  • Arm Cortex X1

    HW
    Arm
    all versions
  • Arm Cortex X1c

    HW
    Arm
    all versions
  • Arm Cortex X1c Firmware

    OS
    Arm
    all versions
  • Arm Cortex X1 Firmware

    OS
    Arm
    all versions
  • Arm Cortex X2

    HW
    Arm
    all versions
  • Arm Cortex X2 Firmware

    OS
    Arm
    all versions
  • Arm Cortex X3

    HW
    Arm
    all versions
  • Arm Cortex X3 Firmware

    OS
    Arm
    all versions
  • Arm Cortex X4

    HW
    Arm
    all versions
  • Arm Cortex X4 Firmware

    OS
    Arm
    all versions
  • Arm Cortex X925

    HW
    Arm
    all versions
  • Arm Cortex X925 Firmware

    OS
    Arm
    all versions
  • Arm Neoverse N2

    HW
    Arm
    all versions
  • Arm Neoverse N2 Firmware

    OS
    Arm
    all versions
  • Arm Neoverse V1

    HW
    Arm
    all versions
  • Arm Neoverse V1 Firmware

    OS
    Arm
    all versions
  • Arm Neoverse V2

    HW
    Arm
    all versions
  • Arm Neoverse V2 Firmware

    OS
    Arm
    all versions
  • Arm Neoverse V3

    HW
    Arm
    all versions
  • Arm Neoverse V3ae

    HW
    Arm
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-0647HIGH7.9same product

In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidati...

CVE-2022-48251HIGH7.5same product

The AES instructions on the ARMv8 platform do not have an algorithm that is "intrinsically resistant" to side-...

CVE-2024-7881MEDIUM5.1same product

An unprivileged context can trigger a data memory-dependent prefetch engine to fetch the contents of a privile...

CVE-2023-34320MEDIUM5.5same product

Cortex-A77 cores (r0p0 and r1p0) are affected by erratum 1508412 where software, under certain circumstances, ...

CVE-2022-23960MEDIUM5.6same product

Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka ...