Linux Kernel Vulnerability in Arm FF-A Driver Registration Process
CVE-2026-64166

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-64166?

In the Linux kernel, a vulnerability exists wherein the bus match callback improperly assumes that every FF-A driver provides an id_table and dereferences it without any checks. This oversight can lead to potential crashes of the bus if a faulty client driver is registered. The resolution enforces a strict check during the registration process, ensuring that the contract is upheld and enhancing overall system robustness against buggy drivers.

Affected Version(s)

Linux 92743071464fca5acbbe812d9a0d88de3eaaad36

Linux 92743071464fca5acbbe812d9a0d88de3eaaad36

Linux 92743071464fca5acbbe812d9a0d88de3eaaad36

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.