hen using Arm Cortex-M Security Extensions (CMSE), Secure stack contents can be leaked to Non-secure state via floating-point registers when a Secure to Non-secure function call is made that returns a floating-point value and when this is the first use of floating-point since entering Secure state. This allows an attacker to read a limited quantity of Secure stack contents with an impact on confidentiality. This issue is specific to code generated using LLVM-based compilers.
| Link | Resource |
|---|---|
| https://developer.arm.com/Arm%20Security%20Center/Cortex-M%20Security%20Extensions%20Vulnerability | Vendor Advisory Exploit |
Configuration 1 (hide)
|
23 Dec 2025, 15:30
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| References | () https://developer.arm.com/Arm%20Security%20Center/Cortex-M%20Security%20Extensions%20Vulnerability - Vendor Advisory, Exploit | |
| CPE | cpe:2.3:a:arm:arm_compiler_for_functional_safety:6.6:*:*:*:*:*:*:* cpe:2.3:a:arm:clang:*:*:*:*:*:*:*:* cpe:2.3:a:arm:arm_compiler_for_embedded_fusa:6.16:*:*:*:lts:*:*:* cpe:2.3:a:arm:arm_compiler_for_embedded:*:*:*:*:*:*:*:* cpe:2.3:a:arm:arm_compiler_for_embedded_fusa:6.21:*:*:*:lts:*:*:* |
|
| First Time |
Arm arm Compiler For Embedded Fusa
Arm arm Compiler For Embedded Arm clang Arm Arm arm Compiler For Functional Safety |
31 Oct 2024, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2024-10-31 17:15
Updated : 2025-12-23 15:30
NVD link : CVE-2024-7883
Mitre link : CVE-2024-7883
CVE.ORG link : CVE-2024-7883
JSON object : View
Sensitive Information in Resource Not Removed Before Reuse