Vulnerability Details CVE-2023-46837
                Arm provides multiple helpers to clean & invalidate the cache
for a given region.  This is, for instance, used when allocating
guest memory to ensure any writes (such as the ones during scrubbing)
have reached memory before handing over the page to a guest.
Unfortunately, the arithmetics in the helpers can overflow and would
then result to skip the cache cleaning/invalidation.  Therefore there
is no guarantee when all the writes will reach the memory.
This undefined behavior was meant to be addressed by XSA-437, but the
approach was not sufficient.
                
                    Exploit prediction scoring system (EPSS) score
                    
                        
                            EPSS Score 0.001
                        
                    
                    
                        
                            EPSS Ranking 15.9%
                        
                    
                 
                
                    CVSS Severity
                    
                        
                            CVSS v3 Score 3.3
                        
                    
                    
                 
                
                
                
                    
                
                
                    
                        Products affected by CVE-2023-46837