CVE-2017-7563: Trustedfirmware Trusted Firmware-A
High severity, CVSS 8.1. EPSS: 0.9% chance of exploitation in the next 30 days.
In ARM Trusted Firmware 1.3, RO memory is always executable at AArch64 Secure EL1, allowing attackers to bypass the MT_EXECUTE_NEVER protection mechanism. This issue occurs because of inconsistency in the number of execute-never bits (one bit versus two bits).
Affected products
- Trustedfirmware Trusted Firmware-A: up to and including 1.3
Published 2017-06-07. Last modified 2026-06-17.