CVE-2025-0647
In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a TLBI is issued to the PE, either by the same PE or another PE in the shareability domain.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.17%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a TLBI is issued to the PE, either by the same PE or another PE in the shareability domain. In this case, the PE may retain stale TLB entries which should have been invalidated by the TLBI.
- CVSS 3.1
- 7.9 HIGHCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
- EPSS
- 0.17% probability · 7th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-226
- Affected
- arm/c1-ultra firmware · arm/c1-premium firmware · arm/cortex-a710 firmware · arm/cortex-x2 firmware · arm/cortex-x3 firmware · arm/cortex-x4 firmware · arm/cortex-x925 firmware · arm/neoverse-v2 firmware · arm/neoverse-v3 firmware · arm/neoverse-v3ae firmware · arm/neoverse-n2 firmware
- Source
- arm-security@arm.com
References
- https://developer.arm.com/documentation/111546Vendor Advisory
- https://graph.volerion.com/view?ID=CVE-2025-0647Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.