CVE-2025-0647
Last modified
CVE-2025-0647 is a high-severity vulnerability rated 7.9/10 on the CVSS scale. In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a TLBI is issued to the PE, either by the same PE or another PE in the shareability domain. In this case, the PE may retain stale TLB entries which should have been invalidated by the TLBI.. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a TLBI is issued to the PE, either by the same PE or another PE in the shareability domain. In this case, the PE may retain stale TLB entries which should have been invalidated by the TLBI.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Arm | C1-Ultra Firmware | All versions |
| Arm | C1-Premium Firmware | All versions |
| Arm | Cortex-A710 Firmware | All versions |
| Arm | Cortex-X2 Firmware | All versions |
| Arm | Cortex-X3 Firmware | All versions |
| Arm | Cortex-X4 Firmware | All versions |
| Arm | Cortex-X925 Firmware | All versions |
| Arm | Neoverse-V2 Firmware | All versions |
| Arm | Neoverse-V3 Firmware | All versions |
| Arm | Neoverse-V3ae Firmware | All versions |
| Arm | Neoverse-N2 Firmware | All versions |
References
- https://developer.arm.com/documentation/111546Vendor Advisory
- https://graph.volerion.com/view?ID=CVE-2025-0647Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-0647?
How severe is CVE-2025-0647?
How do I fix CVE-2025-0647?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-0639An issue has been discovered affecting service availability …7.5
- CVE-2025-0640Authorization Bypass Through User-Controlled Key vulnerabili…4.7
- CVE-2025-0642Use of Hard-coded Credentials, Authorization Bypass Through …6.3
- CVE-2025-0643Improper Neutralization of Input During Web Page Generation …7.2
- CVE-2025-0645Unrestricted Upload of File with Dangerous Type vulnerabilit…7.2
- CVE-2025-0646Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-0648Unexpected server crash in database driver in M-Files Server…4.9
- CVE-2025-0649Incorrect JSON input stringification in Google's Tensorflow …7.5
- CVE-2025-0650A flaw was found in the Open Virtual Network (OVN). Speciall…8.1
- CVE-2025-0651Improper Privilege Management vulnerability in Cloudflare WA…7.1
- CVE-2025-0652An issue has been discovered in GitLab EE/CE affecting all v…6.5
- CVE-2025-0654Rejected reason: This CVE ID has been rejected or withdrawn …
Are you affected by CVE-2025-0647?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
