In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a TLBI is issued to the PE, either by the same PE or another PE in the shareability domain. In this case, the PE may retain stale TLB entries which should have been invalidated by the TLBI.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:NArm C1 Premium
HWArmall versionsArm C1 Premium Firmware
OSArmall versionsArm C1 Ultra
HWArmall versionsArm C1 Ultra Firmware
OSArmall versionsArm Cortex A710
HWArmall versionsArm Cortex A710 Firmware
OSArmall versionsArm Cortex X2
HWArmall versionsArm Cortex X2 Firmware
OSArmall versionsArm Cortex X3
HWArmall versionsArm Cortex X3 Firmware
OSArmall versionsArm Cortex X4
HWArmall versionsArm Cortex X4 Firmware
OSArmall versionsArm Cortex X925
HWArmall versionsArm Cortex X925 Firmware
OSArmall versionsArm Neoverse N2
HWArmall versionsArm Neoverse N2 Firmware
OSArmall versionsArm Neoverse V2
HWArmall versionsArm Neoverse V2 Firmware
OSArmall versionsArm Neoverse V3
HWArmall versionsArm Neoverse V3ae
HWArmall versionsArm Neoverse V3ae Firmware
OSArmall versionsArm Neoverse V3 Firmware
OSArmall versions
Related vulnerabilities
Arm Cortex/Neoverse: obejście ochrony Stage-2 przez Hardware Page Aggregation
An unprivileged context can trigger a data memory-dependent prefetch engine to fetch the contents of a privile...
Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka ...
Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the C...
RCE przez deserializację kontekstu SSL w Mbed TLS