CVE-2017-5925: Allwinner a64

High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.

Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern Intel processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.

Affected products

  • Allwinner a64: affected versions not specified
  • AMD Athlon Ii 640 x4: affected versions not specified
  • AMD E-350: affected versions not specified
  • AMD Fx-8120 8-Core: affected versions not specified
  • AMD Fx-8320 8-Core: affected versions not specified
  • AMD Fx-8350 8-Core: affected versions not specified
  • AMD Phenom 9550 4-Core: affected versions not specified
  • Intel Atom c2750: affected versions not specified
  • Intel Celeron n2840: affected versions not specified
  • Intel Core i5 m480: affected versions not specified
  • Intel Core i7-2620qm: affected versions not specified
  • Intel Core i7-3632qm: affected versions not specified
  • Intel Core i7-4500u: affected versions not specified
  • Intel Core i7-6700k: affected versions not specified
  • Intel Core i7 920: affected versions not specified
  • Intel Xeon e3-1240 v5: affected versions not specified
  • Intel Xeon e5-2658 v2: affected versions not specified
  • NVIDIA Tegra k1 CD570M-a1: affected versions not specified
  • NVIDIA Tegra k1 CD580M-a1: affected versions not specified
  • Samsung Exynos 5800: affected versions not specified

Published 2017-02-27. Last modified 2026-06-17.