Use of Hardware Page Aggregation (HPA) and Stage-1 and/or Stage-2 translation on Cortex-A77, Cortex-A78, Cortex-A78C, Cortex-A78AE, Cortex-A710, Cortex-X1, Cortex-X1C, Cortex-X2, Cortex-X3, Cortex-X4, Cortex-X925, Neoverse V1, Neoverse V2, Neoverse V3, Neoverse V3AE, Neoverse N2 may permit bypass of Stage-2 translation and/or GPT protection.
The Hardware Page Aggregation (HPA) mechanism is used to combine multiple small memory pages into larger blocks to optimize address translation performance. When combined with Stage-1 and/or Stage-2 translation, applied in virtualized environments to isolate guest memory from the host, HPA can be exploited in a way that bypasses Stage-2 verification or GPT protection. Granule Protection Table (GPT) is a mechanism protecting specific memory areas from access at lower privilege levels, such as the normal world of the operating system. Improper interaction of HPA with these translation mechanisms allows access to memory areas that should be protected.
An attacker can gain unauthorized access to protected memory areas, potentially compromising the confidentiality, integrity, and availability of data, including data processed by the hypervisor or Trusted Execution Environment (TEE). This could lead to breaking virtual machine isolation or bypassing system security mechanisms.
Apply patches available from the manufacturer according to references published by Arm Security Center at https://developer.arm.com/Arm%20Security%20Center/Arm%20CPU%20Vulnerability%20CVE-2024-5660. OEM device manufacturers based on the mentioned cores should provide appropriate firmware updates. Monitor security communications from operating system vendors and virtualization platform providers utilizing these processors.
Arm processors: Cortex-A77, Cortex-A78, Cortex-A78C, Cortex-A78AE, Cortex-A710, Cortex-X1, Cortex-X1C, Cortex-X2, Cortex-X3, Cortex-X4, Cortex-X925, Neoverse V1, Neoverse V2, Neoverse V3, Neoverse V3AE, Neoverse N2 — specific firmware versions indicated in manufacturer references
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HArm Cortex A710
HWArmall versionsArm Cortex A710 Firmware
OSArmall versionsArm Cortex A77
HWArmall versionsArm Cortex A77 Firmware
OSArmall versionsArm Cortex A78
HWArmall versionsArm Cortex A78ae
HWArmall versionsArm Cortex A78ae Firmware
OSArmall versionsArm Cortex A78c
HWArmall versionsArm Cortex A78c Firmware
OSArmall versionsArm Cortex A78 Firmware
OSArmall versionsArm Cortex X1
HWArmall versionsArm Cortex X1c
HWArmall versionsArm Cortex X1c Firmware
OSArmall versionsArm Cortex X1 Firmware
OSArmall versionsArm Cortex X2
HWArmall versionsArm Cortex X2 Firmware
OSArmall versionsArm Cortex X3
HWArmall versionsArm Cortex X3 Firmware
OSArmall versionsArm Cortex X4
HWArmall versionsArm Cortex X4 Firmware
OSArmall versionsArm Cortex X925
HWArmall versionsArm Cortex X925 Firmware
OSArmall versionsArm Neoverse N2
HWArmall versionsArm Neoverse N2 Firmware
OSArmall versionsArm Neoverse V1
HWArmall versionsArm Neoverse V1 Firmware
OSArmall versionsArm Neoverse V2
HWArmall versionsArm Neoverse V2 Firmware
OSArmall versionsArm Neoverse V3
HWArmall versionsArm Neoverse V3ae
HWArmall versions
Related vulnerabilities
In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidati...
The AES instructions on the ARMv8 platform do not have an algorithm that is "intrinsically resistant" to side-...
An unprivileged context can trigger a data memory-dependent prefetch engine to fetch the contents of a privile...
Cortex-A77 cores (r0p0 and r1p0) are affected by erratum 1508412 where software, under certain circumstances, ...
Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka ...