Out-of-Bounds Write Vulnerability in Linux Kernel Affecting Firmware Components
CVE-2026-68401

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-68401?

A vulnerability in the Linux kernel's firmware component may allow for out-of-bounds writes within the ffa_setup_and_transmit function. The issues arise from a mismatch in expected sizes when handling certain FFA versions, leading to possible data corruption or unexpected behavior. Specifically, if FFA versions are less than 1.2, the function may incorrectly calculate sizes, causing potential out-of-bounds writes when accessing reserved structures. To address this, modifications have been made to ensure that structures are appropriately zeroed out and that sufficient sizes are allocated for writes.

Affected Version(s)

Linux 111a833dc5cbef3d05b2a796a7e23cb7f6ff2192

Linux 111a833dc5cbef3d05b2a796a7e23cb7f6ff2192 < 27abdaf0c5c89b06694e4c3d8318e8d6a60c1d1b

Linux 111a833dc5cbef3d05b2a796a7e23cb7f6ff2192 < 3383ffb7ef937317361713ffcc21921a7848511a

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.