Endpoint Memory Access Descriptor Vulnerability in Linux Kernel by Linux Foundation
CVE-2026-68400

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-68400?

A vulnerability in the Linux Kernel's firmware component was identified related to the Endpoint Memory Access Descriptor offset calculation. This issue involves using the incorrect configuration for determining the starting point of the endpoint memory access array. By adhering to the Functional Framework for Arm (FF-A) specification, it ensures proper offset calculations through the use of the ep_mem_offset. Furthermore, enhancements were made to the workflow by relocating the ffa_mem_region_additional_setup() function to occur earlier in the setup process, alongside the introduction of sanity checks that verify that these calculated offsets do not exceed the defined maximum fragment size.

Affected Version(s)

Linux 113580530ee7dc61e668b641d657920734533b9f

Linux 113580530ee7dc61e668b641d657920734533b9f < 8ef18f0ab3c0ec1eac77289f5a542bd96a8a6d66

Linux 113580530ee7dc61e668b641d657920734533b9f

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.