CVE-2024-7883 - CVE House
Back to Database
Status published Low CVE-2024-7883

CMSE secure state may leak from stack to floating-point registers

Vulnerability Description

When using Arm Cortex-M Security Extensions (CMSE), Secure stack contents can be leaked to Non-secure state via floating-point registers when a Secure to Non-secure function call is made that returns a floating-point value and when this is the first use of floating-point since entering Secure state. This allows an attacker to read a limited quantity of Secure stack contents with an impact on confidentiality. This issue is specific to code generated using LLVM-based compilers.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-7883

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Arm Compiler for Embedded, Arm Compiler for Embedded FuSa 6.16LTS, Arm Compiler for Embedded FuSa 6.21, Arm Compiler for Functional Safety 6.6, CLang
Vulnerable Versions:
6.6, All versions, 13

Timeline

Official Publish: October 31st, 2024
Last Modified: October 31st, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.