CVE-2017-9607: Integer Overflow
The BL1 FWU SMC handling code in ARM Trusted Firmware before 1.4 might allow attackers to write arbitrary data to secure memory, bypass the bl1platmemcheck protection mechanism, cause a denial of service, or possibly have unspecified other impact via a crafted AArch32 image, which triggers an integer overflow.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9607?
CVE-2017-9607 has a high severity rating due to its potential to allow arbitrary data writes to secure memory.
How do I fix CVE-2017-9607?
Upgrading to ARM Trusted Firmware version 1.4 or later mitigates the vulnerability in CVE-2017-9607.
What are the potential impacts of CVE-2017-9607?
CVE-2017-9607 can lead to denial of service, unauthorized memory access, and other unspecified effects.
Which versions of ARM Trusted Firmware are affected by CVE-2017-9607?
CVE-2017-9607 affects ARM Trusted Firmware versions prior to 1.4.
What type of attack does CVE-2017-9607 enable?
CVE-2017-9607 enables attackers to bypass memory protection and potentially execute arbitrary code via crafted AArch32 images.