← Back

Arm

arm

193 CVEs • 141 products

Products (141)

Click to collapse
Toggle
Mbed Tls
mbed_tls
Mbed Os
mbed-os
Cortex A
cortex-a
Mbed
mbed
Tf Psa Crypto
tf-psa-crypto
Mbed Crypto
mbed_crypto
Arm Compiler
arm_compiler
Scp Firmware
scp_firmware
Cortex A72
cortex-a72
Fast Models
fast_models
Cortex R
cortex-r
Mbed Mqtt
mbed-mqtt
Mbed Coap
mbed-coap
Cmsis Rtos
cmsis-rtos
Mbed Ualloc
mbed_ualloc
Gnu Toolchain
gnu_toolchain
Keil Mdk
keil_mdk
Linaro Forge
linaro_forge
Mbed Studio
mbed_studio
Clang
clang
Cortex R7
cortex-r7
Cortex R8
cortex-r8
Cortex A8
cortex-a8
Cortex A9
cortex-a9
Cortex A12
cortex-a12
Cortex A15
cortex-a15

CVEs (193)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Arm
3Bifrost Gpu Kernel Driver
Midguard Gpu Kernel DriverValhall Gpu Kernel Driver
Nov 21, 2024
May 19, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Arm Mali GPU Kernel Driver has a use-after-free: Midgard r28p0 through r29p0 before r30p0, Bifrost r17p0 through r23p0 before r24p0, and Valhall r19p0 through r23p0 before r24p0.
1Arm
3Bifrost Gpu Kernel Driver
Midgard Gpu Kernel DriverValhall Gpu Kernel Driver
Nov 21, 2024
May 19, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Arm Mali GPU Kernel Driver (Midgard r4p0 through r31p0, Bifrost r0p0 through r36p0 before r37p0, and Valhall r19p0 through r36p0 before r37p0) allows improper GPU memory operations to reach a use-after-free situation.
1Arm
1Mbed
Nov 21, 2024
May 3, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ARM mbed product Version 6.3.0 is vulnerable to integer wrap-around in malloc_wrapper function, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/e...Show more
ARM mbed product Version 6.3.0 is vulnerable to integer wrap-around in malloc_wrapper function, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.Show less
1Arm
1Mbed Ualloc
Nov 21, 2024
May 3, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ARM mbed-ualloc memory library version 1.3.0 is vulnerable to integer wrap-around in function mbed_krbs, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code in...Show more
ARM mbed-ualloc memory library version 1.3.0 is vulnerable to integer wrap-around in function mbed_krbs, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.Show less
1Arm
1Cmsis Rtos
Nov 21, 2024
May 3, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ARM CMSIS RTOS2 versions prior to 2.1.3 are vulnerable to integer wrap-around inosRtxMemoryAlloc (local malloc equivalent) function, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as...Show more
ARM CMSIS RTOS2 versions prior to 2.1.3 are vulnerable to integer wrap-around inosRtxMemoryAlloc (local malloc equivalent) function, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or injected code execution.Show less
2Arm
Debian
2Debian Linux
Mbed Tls
Dec 2, 2025
Mar 24, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an input password's length is 0.
3Arm
DebianXen
22Cortex A57 Firmware
Cortex A65 FirmwareCortex A65ae Firmware+19 more
Nov 21, 2024
Mar 13, 2022
N/A· v4
5.6 MEDIUM· v3
1.9 LOW· v2
Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influenc...Show more
Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive information.Show less
2Amperecomputing
Arm
22Ampere Altra Firmware
Ampere Altra Max FirmwareCortex A15 Firmware+19 more
Nov 21, 2024
Mar 10, 2022
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the CPU BHB) to influence mispredicted branches in the victim's hardware context. Speculation caused by these mispr...Show more
Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the CPU BHB) to influence mispredicted branches in the victim's hardware context. Speculation caused by these mispredicted branches can then potentially be used to cause cache allocation, which can then be used to infer information that should be protected.Show less
1Arm
3Bifrost Gpu Kernel Driver
Midgard Gpu Kernel DriverValhall Gpu Kernel Driver
Nov 3, 2025
Mar 3, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects Midgard r26p0 through r31p0, Bifrost r0p0 through r35p0, and Valhall r19p0 through r35p0.
1Arm
1Trusted Firmware M
Nov 27, 2024
Mar 1, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Trusted Firmware M 1.4.x through 1.4.1 has a buffer overflow issue in the Firmware Update partition. In the IPC model, a psa_fwu_write caller from SPE or NSPE can overwrite stack memory locations.
1Arm
1Adaptive Scalable Texture Compression Encoder
Nov 21, 2024
Feb 28, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
ARM astcenc 3.2.0 is vulnerable to Buffer Overflow in function encode_ise().
1Arm
1Adaptive Scalable Texture Compression Encoder
Nov 21, 2024
Feb 28, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ARM astcenc 3.2.0 is vulnerable to Buffer Overflow. When the compression function of the astc-encoder project with -cl option was used, a stack-buffer-overflow occurred in function encode_ise() in function compress_symbo...Show more
ARM astcenc 3.2.0 is vulnerable to Buffer Overflow. When the compression function of the astc-encoder project with -cl option was used, a stack-buffer-overflow occurred in function encode_ise() in function compress_symbolic_block_for_partition_2planes() in "/Source/astcenc_compress_symbolic.cpp".Show less
1Arm
3Bifrost Gpu Kernel Driver
Midgard Gpu Kernel DriverValhall Gpu Kernel Driver
Nov 21, 2024
Jan 14, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Arm Mali GPU Kernel Driver (Midgard r26p0 through r30p0, Bifrost r0p0 through r34p0, and Valhall r19p0 through r34p0) allows a non-privileged user to achieve write access to read-only memory, and possibly obtain root pri...Show more
Arm Mali GPU Kernel Driver (Midgard r26p0 through r30p0, Bifrost r0p0 through r34p0, and Valhall r19p0 through r34p0) allows a non-privileged user to achieve write access to read-only memory, and possibly obtain root privileges, corrupt memory, and modify the memory of other processes.Show less
2Arm
Fedoraproject
2Fedora
Mbed Tls
Nov 21, 2024
Dec 21, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Mbed TLS before 3.1.0, psa_aead_generate_nonce allows policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.
2Arm
Fedoraproject
2Fedora
Mbed Tls
Nov 21, 2024
Dec 21, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Mbed TLS before 2.28.0 and 3.x before 3.1.0, psa_cipher_generate_iv and psa_cipher_encrypt allow policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted applic...Show more
In Mbed TLS before 2.28.0 and 3.x before 3.1.0, psa_cipher_generate_iv and psa_cipher_encrypt allow policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.Show less
2Arm
Debian
2Debian Linux
Mbed Tls
Nov 3, 2025
Dec 20, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.
1Arm
4China Star Mc1 Firmware
Cortex M33 FirmwareCortex M35p Firmware+1 more
Nov 21, 2024
Aug 23, 2021
N/A· v4
3.4 LOW· v3
3.6 LOW· v2
Certain Arm products before 2021-08-23 do not properly consider the effect of exceptions on a VLLDM instruction. A Non-secure handler may have read or write access to part of a Secure context. This affects Arm Cortex-M33...Show more
Certain Arm products before 2021-08-23 do not properly consider the effect of exceptions on a VLLDM instruction. A Non-secure handler may have read or write access to part of a Secure context. This affects Arm Cortex-M33 r0p0 through r1p0, Arm Cortex-M35P r0, Arm Cortex-M55 r0p0 through r1p0, and Arm China STAR-MC1 (in the STAR SE configuration).Show less
3Arm
DebianSiemens
8Debian Linux
Logo! Cmr2020 FirmwareLogo! Cmr2040 Firmware+5 more
Nov 21, 2024
Aug 23, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certificate is considered va...Show more
An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certificate is considered valid. However, if the parameters do not match in any way, then the certificate should be considered invalid.Show less
1Arm
1Mbed Tls
Nov 21, 2024
Aug 23, 2021
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Mbed TLS before 2.24.0. The verification of X.509 certificates when matching the expected common name (the cn argument of mbedtls_x509_crt_verify) with the actual certificate name is mishandled...Show more
An issue was discovered in Mbed TLS before 2.24.0. The verification of X.509 certificates when matching the expected common name (the cn argument of mbedtls_x509_crt_verify) with the actual certificate name is mishandled: when the subjecAltName extension is present, the expected name is compared to any name in that extension regardless of its type. This means that an attacker could impersonate a 4-byte or 16-byte domain by getting a certificate for the corresponding IPv4 or IPv6 address (this would require the attacker to control that IP address, though).Show less
2Arm
Debian
2Debian Linux
Mbed Tls
Nov 21, 2024
Aug 23, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS). There is missing zeroization of plaintext buffers in mbedtls_ssl_read to erase unused application data from memory.