PT-2024-36907 · Arm+2 · Arm Cortex-A78+11

Published

2024-12-10

·

Updated

2026-01-05

·

CVE-2024-5660

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Arm Cortex processors versions A77 through X925, including A78, A78C, A78AE, A710, X1, X1C, X2, X3, X4, Neoverse V1, Neoverse V2, Neoverse V3, Neoverse V3AE, Neoverse N2
Description The use of Hardware Page Aggregation (HPA) and Stage-1 and/or Stage-2 translation on affected Arm Cortex processors may permit bypass of Stage-2 translation and/or GPT protection.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-5660
OPENSUSE-SU-2025_0557-1
SUSE-SU-2025:0236-1
SUSE-SU-2025:0289-1
SUSE-SU-2025:0557-1
SUSE-SU-2025:20166-1
SUSE-SU-2025:20249-1
SUSE-SU-2025_0236-1
SUSE-SU-2025_0557-1

Affected Products

Arm Cortex-A710
Arm Cortex-A77
Arm Cortex-A78
Arm Cortex-X1
Arm Cortex-X2
Arm Cortex-X3
Arm Cortex-X4
Arm Neoverse N2
Arm Neoverse V1
Arm Neoverse V3
Debian
Suse