CVE-2017-7563: High severity Arm ARM Trusted Firmware vulnerability
In ARM Trusted Firmware 1.3, RO memory is always executable at AArch64 Secure EL1, allowing attackers to bypass the MTEXECUTENEVER protection mechanism. This issue occurs because of inconsistency in the number of execute-never bits (one bit versus two bits).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7563?
CVE-2017-7563 is classified as a high-severity vulnerability due to its potential to allow unauthorized code execution in a secure environment.
How do I fix CVE-2017-7563?
To mitigate CVE-2017-7563, update the ARM Trusted Firmware to a version later than 1.3, which addresses the execute-never bit inconsistency.
What are the potential impacts of CVE-2017-7563?
CVE-2017-7563 can lead to exploits that bypass the MT_EXECUTE_NEVER protection and allow attackers to execute code in read-only memory.
Which versions of ARM Trusted Firmware are affected by CVE-2017-7563?
All versions of ARM Trusted Firmware up to and including 1.3 are affected by CVE-2017-7563.
Is there a workaround for CVE-2017-7563 if I cannot update?
No reliable workaround is available for CVE-2017-7563; the recommended action is to upgrade to a patched version of the firmware.