Back

LOW

CMSE secure state may leak from stack to floating-point registers

Published Oct 31, 2024

Description

When using Arm Cortex-M Security Extensions (CMSE), Secure stack contents can be leaked to Non-secure state via floating-point registers when a Secure to Non-secure function call is made that returns a floating-point value and when this is the first use of floating-point since entering Secure state. This allows an attacker to read a limited quantity of Secure stack contents with an impact on confidentiality. This issue is specific to code generated using LLVM-based compilers.

Affected products

Remediation

Vendor solution

Recompile affected code using a fixed compiler.

Metrics

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Arm
Published Oct 31, 2024
Updated Oct 31, 2024
Reserved Aug 16, 2024
CISA Vulnrichment
Updated Oct 31, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Oct 31, 2024