Buffer Overflow Vulnerability in Linux Kernel Affecting Firmware Interaction
CVE-2026-64520
What is CVE-2026-64520?
A vulnerability has been identified in the Linux kernel's handling of firmware data, specifically in the 'arm_ffa' module. This security flaw resides in the PARTITION_INFO_GET_REGS function, where improper validation of firmware-provided indices could lead to a buffer overflow. If an attacker were to exploit this weakness, they could send inconsistent counts or index progressions, causing the copy operation to write beyond allocated memory space. The issue has been addressed by ensuring that the counts and index progressions are correctly validated, thus enhancing the integrity of memory management within the kernel.
Affected Version(s)
Linux ba85c644ac8dc37d9b01a3332c2f142cb4d46954
Linux ba85c644ac8dc37d9b01a3332c2f142cb4d46954 < 79d95c02ae0a95e6e80e8e92b7ca74ecee02854f
Linux ba85c644ac8dc37d9b01a3332c2f142cb4d46954 < 3974ea1938406f9bfa7c1f48d4e43533f447bb08