CVE-2017-9607: Trustedfirmware Trusted Firmware-A

High severity, CVSS 7.0. EPSS: 0.8% chance of exploitation in the next 30 days.

The BL1 FWU SMC handling code in ARM Trusted Firmware before 1.4 might allow attackers to write arbitrary data to secure memory, bypass the bl1_plat_mem_check protection mechanism, cause a denial of service, or possibly have unspecified other impact via a crafted AArch32 image, which triggers an integer overflow.

Affected products

Published 2017-09-20. Last modified 2026-06-17.