cbcvebase.
CVE-2024-7881
published 2025-01-28

CVE-2024-7881: An unprivileged context can trigger a data memory-dependent prefetch engine to fetch the contents of a privileged location and consume those contents as an…

medium5.1CVSS 3.1
AVLACLPRNUINSUCLILAN
An unprivileged context can trigger a data memory-dependent prefetch engine to fetch the contents of a privileged location and consume those contents as an address that is also dereferenced.

Affected

13 ranges
VendorProductVersion rangeFixed in
armarm-trusted-firmware>= 0 < 2.12.1+dfsg-12.12.1+dfsg-1
armarm-trusted-firmware>= 0 < 2.12.1+dfsg-12.12.1+dfsg-1
armc1-premium
armc1-pro
armc1-ultra
armcortex-x3
armcortex-x4
armcortex-x925
armneoverse_v2
armneoverse_v3
armneoverse_v3ae
debianarm-trusted-firmware< arm-trusted-firmware 2.12.1+dfsg-1 (forky)arm-trusted-firmware 2.12.1+dfsg-1 (forky)
googleandroid

CVSS provenance

nvdv3.15.1MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
osv5.1MEDIUM