{"id": "CVE-2025-0647", "cveTags": [], "metrics": {"cvssMetricV31": [{"type": "Secondary", "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "cvssData": {"scope": "CHANGED", "version": "3.1", "baseScore": 7.9, "attackVector": "LOCAL", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "HIGH", "confidentialityImpact": "HIGH"}, "impactScore": 5.8, "exploitabilityScore": 1.5}]}, "published": "2026-01-14T11:15:50.027", "references": [{"url": "https://developer.arm.com/documentation/111546", "tags": ["Vendor Advisory"], "source": "arm-security@arm.com"}, {"url": "https://graph.volerion.com/view?ID=CVE-2025-0647", "tags": ["Third Party Advisory"], "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Secondary", "source": "arm-security@arm.com", "description": [{"lang": "en", "value": "CWE-226"}]}], "descriptions": [{"lang": "en", "value": "In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a TLBI is issued to the PE, either by the same PE or another PE in the shareability domain. In this case, the PE may retain stale TLB entries which should have been invalidated by the TLBI."}], "lastModified": "2026-01-26T19:40:19.270", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:arm:c1-ultra_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "46FBFC11-C12A-44A7-9EE0-504FFDEA7BC3"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:arm:c1-ultra:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "501E45AC-8E1E-4095-9771-04C739A864BB"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:arm:c1-premium_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "697A11F4-9A13-4DC4-90AD-A2CB215D5BCF"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:arm:c1-premium:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "1C6B2962-3F19-46B9-A74A-521FF4ECC357"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:arm:cortex-a710_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2AF7E5CA-95FF-4242-BD6E-8BDC185DA095"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:arm:cortex-a710:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7CEEC509-2A56-48F1-B388-3A8660D58FB5"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:arm:cortex-x2_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7B749251-B873-4E37-BB5C-1D4C021205D3"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:arm:cortex-x2:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "5D7FB822-DD26-402E-A413-EF55B6C01D07"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:arm:cortex-x3_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E776B4A0-0642-489C-B03B-F6B9FFDFFD11"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:arm:cortex-x3:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "979779A2-D556-4EF5-932D-F38009186B91"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:arm:cortex-x4_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4F8394E0-E173-41B5-B13D-6F45947D46E6"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:arm:cortex-x4:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "63E0897F-9D56-4835-8C12-B3758CF38F96"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:arm:cortex-x925_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BF2C4EC2-711A-407A-A8F4-7E7134B4F06E"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:arm:cortex-x925:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "B1CE6CA3-E32E-4892-A7DB-D4A879956320"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:arm:neoverse-v2_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "96E7E713-E11C-45CB-83E7-C21F57720A55"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:arm:neoverse-v2:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7DF8B63B-C2E7-4C97-BA5C-79E2278F0C52"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:arm:neoverse-v3_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F0E84400-B02D-4B8D-9179-5428D38641CF"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:arm:neoverse-v3:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "EFC574FE-7462-4E50-AE4A-5204C339C1F0"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:arm:neoverse-v3ae_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C0CDE1B2-393F-4D2A-B872-3317B26D06B3"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:arm:neoverse-v3ae:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "66BD33A8-6D01-4A63-B81E-E974CDFAD04A"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:arm:neoverse-n2_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CFB97E2D-7619-4D4F-9031-EDDF960BA2B9"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:arm:neoverse-n2:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "3DE25602-E9D8-494D-8AEF-A2A9007599DD"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "arm-security@arm.com"}