CVE-2025-0647 Details
Description
In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a TLBI is issued to the PE, either by the same PE or another PE in the shareability domain. In this case, the PE may retain stale TLB entries which should have been invalidated by the TLBI.
A vulnerability exists in certain Arm CPUs where a CPP RCTX instruction executed on one Processing Element (PE) can prevent proper TLB invalidation. This issue arises when a TLBI is issued to the PE, either by itself or another PE in the shareability domain. As a result, the PE may retain outdated TLB entries that should have been cleared, potentially allowing a modified, untrusted guest OS to compromise the host in certain hypervisor environments.
Affected partners are advised to perform TLB invalidation whenever a CPP RCTX instruction is executed. For specific guidance, consult the Errata Notice for the relevant product.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://graph.volerion.com/view?ID=CVE-2025-0647 | CISA-ADP | Third Party Advisory |
| https://developer.arm.com/documentation/111546 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-226 | Sensitive Information in Resource Not Removed Before Reuse | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| arm c1-ultra firmware | All versions |
CPE
Remediation
| |
| arm c1-ultra | All versions |
CPE
Remediation
| |
| arm c1-premium firmware | All versions |
CPE
Remediation
| |
| arm c1-premium | All versions |
CPE
Remediation
| |
| arm cortex-a710 firmware | All versions |
CPE
Remediation
| |
| arm cortex-a710 | All versions |
CPE
Remediation
| |
| arm cortex-x2 firmware | All versions |
CPE
Remediation
| |
| arm cortex-x2 | All versions |
CPE
Remediation
| |
| arm cortex-x3 firmware | All versions |
CPE
Remediation
| |
| arm cortex-x3 | All versions |
CPE
Remediation
| |
| arm cortex-x4 firmware | All versions |
CPE
Remediation
| |
| arm cortex-x4 | All versions |
CPE
Remediation
| |
| arm cortex-x925 firmware | All versions |
CPE
Remediation
| |
| arm cortex-x925 | All versions |
CPE
Remediation
| |
| arm neoverse-v2 firmware | All versions |
CPE
Remediation
| |
| arm neoverse-v2 | All versions |
CPE
Remediation
| |
| arm neoverse-v3 firmware | All versions |
CPE
Remediation
| |
| arm neoverse-v3 | All versions |
CPE
Remediation
| |
| arm neoverse-v3ae firmware | All versions |
CPE
Remediation
| |
| arm neoverse-v3ae | All versions |
CPE
Remediation
| |
| arm neoverse-n2 firmware | All versions |
CPE
Remediation
| |
| arm neoverse-n2 | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 26, 2026 | Initial Analysis | [email protected] |
| Jan 20, 2026 | CVE Modified | CISA-ADP |
| Jan 15, 2026 | CVE Modified | CISA-ADP |
| Jan 14, 2026 | New CVE Received | [email protected] |