Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2024-7883 Details

Description

When using Arm Cortex-M Security Extensions (CMSE), Secure stack contents can be leaked to Non-secure state via floating-point registers when a Secure to Non-secure function call is made that returns a floating-point value and when this is the first use of floating-point since entering Secure state. This allows an attacker to read a limited quantity of Secure stack contents with an impact on confidentiality. This issue is specific to code generated using LLVM-based compilers.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-226Sensitive Information in Resource Not Removed Before Reuse[email protected]

Affected Products

ProductVersions
arm arm compiler for embedded
>= 6.6, < 6.23

CPE

  • cpe:2.3:a:arm:arm_compiler_for_embedded:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
arm arm compiler for embedded fusa
6.16
6.21

CPE

  • cpe:2.3:a:arm:arm_compiler_for_embedded_fusa:6.16:*:*:*:lts:*:*:*
  • cpe:2.3:a:arm:arm_compiler_for_embedded_fusa:6.21:*:*:*:lts:*:*:*

Remediation

  • No remediation found in references.
arm arm compiler for functional safety
6.6

CPE

  • cpe:2.3:a:arm:arm_compiler_for_functional_safety:6.6:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
arm clang
>= 11.0.0, < 20.1.0

CPE

  • cpe:2.3:a:arm:clang:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

4 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2024-7883
NVD Published Date:
Oct 31, 2024
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2024-7883 Details - Not Deferred