PT-2017-17801 · Arm · Arm Trusted Firmware
CVE-2017-7563
·
Publicado
2017-06-07
·
Atualizado
2026-06-08
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ARM Trusted Firmware version 1.3
Description
The issue in ARM Trusted Firmware allows attackers to bypass the MT EXECUTE NEVER protection mechanism because RO memory is always executable at AArch64 Secure EL1. This is due to an inconsistency in the number of execute-never bits.
Recommendations
For ARM Trusted Firmware version 1.3, consider disabling or restricting access to the execute-never bits mechanism as a temporary workaround until a patch is available.
Correção
Incorrect Permission
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Arm Trusted Firmware