CVE-2022-48251: High severity Arm Cortex-a53 Firmware vulnerability
DISPUTED The AES instructions on the ARMv8 platform do not have an algorithm that is "intrinsically resistant" to side-channel attacks. NOTE: the vendor reportedly offers the position "while power side channel attacks ... are possible, they are not directly caused by or related to the Arm architecture."
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-48251?
CVE-2022-48251 is a vulnerability that affects the AES instructions on the ARMv8 platform.
What is the severity of CVE-2022-48251?
The severity of CVE-2022-48251 is high with a severity value of 7.5.
What software is affected by CVE-2022-48251?
Arm Cortex-a53 Firmware, Arm Cortex-a57 Firmware, Arm Cortex-a72 Firmware, Arm Cortex-a73 Firmware, Arm Cortex-a75 Firmware, Arm Cortex-a76 Firmware, Arm Cortex-a76ae Firmware, Arm Cortex-a77 Firmware, Arm Cortex-a78 Firmware.
Are all ARM Cortex-aXX vulnerable to CVE-2022-48251?
No, not all ARM Cortex-aXX are vulnerable to CVE-2022-48251, only the firmware versions mentioned.
How can I fix CVE-2022-48251?
There is no known fix or patch for CVE-2022-48251 at the moment. It is advised to stay updated with any vendor recommendations or security updates.