CVE-2017-9607

HIGH

ARM Trusted Firmware <1.4 - Memory Corruption

Title source: llm
STIX 2.1

Description

The BL1 FWU SMC handling code in ARM Trusted Firmware before 1.4 might allow attackers to write arbitrary data to secure memory, bypass the bl1_plat_mem_check protection mechanism, cause a denial of service, or possibly have unspecified other impact via a crafted AArch32 image, which triggers an integer overflow.

References (2)

Core 2
Core References

Scores

CVSS v3 7.0
EPSS 0.0019
EPSS Percentile 40.0%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-190
Status published
Products (1)
arm/arm-trusted-firmware < 1.3
Published Sep 20, 2017
Tracked Since Feb 18, 2026