CVE-2017-5927 describes a side-channel vulnerability in the Memory Management Unit (MMU) of modern ARM processors, affecting products from Allwinner, AMD, Intel, NVIDIA, and Samsung. This flaw allows attackers to leak data and code pointers from JavaScript by observing traces left in the last-level cache during virtual-to-physical address translation, effectively bypassing Address Space Layout Randomization (ASLR). With a CVSS score of 7.5 (High), this network-exploitable vulnerability requires no user interaction and has a high impact on confidentiality. While there is no evidence of active exploitation in the wild (not in KEV or Hot List), public exploit code is not readily available, and community discussion and media coverage are limited, suggesting it is not a widely targeted threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:allwinner:a64:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:amd:athlon_ii_640_x4:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:amd:e-350:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:amd:fx-8120_8-core:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:amd:fx-8320_8-core:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.