Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.2%top 95%

CVE-2025-0647: CWE-226 Sensitive Information in Resource Not Removed Before Reuse in Arm Neoverse-N2

0
High
VulnerabilityCVE-2025-0647cvecve-2025-0647cwe-226cloud
Published: 06/09/2026 (06/09/2026, 18:38:16 UTC)
Source: CVE Database V5
Vendor/Project: Arm
Product: Neoverse-N2

Description

CVE-2025-0647 is a vulnerability in the Arm Neoverse-N2 processor where the CPP RCTX instruction can be exploited by an attacker with privileged guest kernel access to prevent TLB invalidations. This may allow unauthorized reading of sensitive data. The issue affects certain Compute Engine Arm VMs (C4A, A4X). Google Cloud has already applied mitigations, and no customer action is required.

CVSS v3.1

Score 7.9high

Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

Affected software

Affected versions
=0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/04/2026, 13:26:33 UTC

Technical Analysis

The vulnerability CVE-2025-0647 involves the CPP RCTX instruction on select Arm Neoverse-N2 processors, which can be used by an attacker with privileged access to the guest kernel to inhibit TLB invalidations from taking effect. This behavior can lead to unauthorized access to sensitive data by bypassing memory protection mechanisms. The vulnerability specifically impacts Compute Engine Arm virtual machines C4A and A4X. Google Cloud has applied mitigations to their Arm server fleet to address this issue.

Potential Impact

An attacker with privileged guest kernel access can exploit this vulnerability to read sensitive data they are not authorized to access by preventing TLB invalidations. This compromises confidentiality but does not affect integrity or availability. The CVSS score is 7.9 (high severity), reflecting the potential for significant data exposure under certain conditions.

Mitigation Recommendations

No customer action is required as Google Cloud has already applied mitigations to the affected Arm server fleet. Users of the affected Compute Engine Arm VMs (C4A, A4X) should verify with their cloud provider for any updates or advisories but do not need to take additional steps.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
Arm
Date Reserved
2025-01-22T14:26:41.767Z
Cvss Version
null
State
PUBLISHED

Threat ID: 6967aad3d0ff220b950c94e1

Added to database: 01/14/2026, 14:40:19 UTC

Last enriched: 08/04/2026, 13:26:33 UTC

Last updated: 08/04/2026, 13:26:33 UTC

Views: 325

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses