8.4

CVE-2026-64520

firmware: arm_ffa: Bound PARTITION_INFO_GET_REGS copies

In the Linux kernel, the following vulnerability has been resolved:

firmware: arm_ffa: Bound PARTITION_INFO_GET_REGS copies

The register-based PARTITION_INFO_GET path trusted the firmware-provided
indices when copying partition descriptors into the caller buffer.
Reject inconsistent counts or index progressions so the copy loop cannot
write past the allocated array.

(fixed cur_idx when exactly one descriptor in the first fragment)
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version ba85c644ac8dc37d9b01a3332c2f142cb4d46954
Version < f39bc7ebe75e2186b417a024a7f7e2fd4cc7eb95
Status affected
Version ba85c644ac8dc37d9b01a3332c2f142cb4d46954
Version < 79d95c02ae0a95e6e80e8e92b7ca74ecee02854f
Status affected
Version ba85c644ac8dc37d9b01a3332c2f142cb4d46954
Version < 3974ea1938406f9bfa7c1f48d4e43533f447bb08
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 6.12
Status affected
Version 0
Version < 6.12
Status unaffected
Version <= 6.18.*
Version 6.18.34
Status unaffected
Version <= 7.0.*
Version 7.0.11
Status unaffected
Version <= *
Version 7.1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.031
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.4 2.5 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/f39bc7ebe75e2186b417a024a7f7e2fd4cc7eb95
https://git.kernel.org/stable/c/79d95c02ae0a95e6e80e8e92b7ca74ecee02854f
https://git.kernel.org/stable/c/3974ea1938406f9bfa7c1f48d4e43533f447bb08