CVE-2020-16273: Arm ARMV8-M Firmware

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

In Arm software implementing the Armv8-M processors (all versions), the stack selection mechanism could be influenced by a stack-underflow attack in v8-M TrustZone based processors. An attacker can cause a change to the stack pointer used by the Secure World from a non-secure application if the stack is not initialized. This vulnerability affects only the software that is based on Armv8-M processors with the Security Extension.

Affected products

  • Arm ARMV8-M Firmware: any version

Published 2020-11-12. Last modified 2026-06-17.