SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2025-0647

In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a TLBI is issued to the PE, either by the same PE or another PE in the shareability domain.

HIGH 7.9EPSS 0.17%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.17%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a TLBI is issued to the PE, either by the same PE or another PE in the shareability domain. In this case, the PE may retain stale TLB entries which should have been invalidated by the TLBI.

CVSS 3.1
7.9 HIGHCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
EPSS
0.17% probability · 7th percentile
CISA KEV
Not listed
Weakness
CWE-226
Affected
arm/c1-ultra firmware · arm/c1-premium firmware · arm/cortex-a710 firmware · arm/cortex-x2 firmware · arm/cortex-x3 firmware · arm/cortex-x4 firmware · arm/cortex-x925 firmware · arm/neoverse-v2 firmware · arm/neoverse-v3 firmware · arm/neoverse-v3ae firmware · arm/neoverse-n2 firmware
Source
arm-security@arm.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.