CVE-2024-7883: Arm Compiler For Embedded
Low severity, CVSS 3.7. EPSS: 0.5% chance of exploitation in the next 30 days.
When using Arm Cortex-M Security Extensions (CMSE), Secure stack contents can be leaked to Non-secure state via floating-point registers when a Secure to Non-secure function call is made that returns a floating-point value and when this is the first use of floating-point since entering Secure state. This allows an attacker to read a limited quantity of Secure stack contents with an impact on confidentiality. This issue is specific to code generated using LLVM-based compilers.
Affected products
- Arm Arm Compiler For Embedded: from 6.6, before 6.23 (fixed in 6.23)
- Arm Arm Compiler For Embedded Fusa: version 6.16 only; version 6.21 only
- Arm Arm Compiler For Functional Safety: version 6.6 only
- Arm Clang: from 11.0.0, before 20.1.0 (fixed in 20.1.0)
Published 2024-10-31. Last modified 2026-06-17.