SB2026081281 - NULL pointer dereference in Linux kernel firmware arm_ffa driver
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2026-68444)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in ffa_partition_info_get() when processing a NULL partition UUID argument. A local attacker can trigger the vulnerable function with a NULL argument to cause a denial of service.
The issue results in a kernel panic.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/12a42c610e4432e7708cc48d607e5903fffe0aad
- https://git.kernel.org/stable/c/7201e56e52d18abf4cd0a2fee45daf9dc08b5b97
- https://git.kernel.org/stable/c/86f5ea90f73bb7154593bb96f3411e197f3d4fbe
- https://git.kernel.org/stable/c/8ae5f8e4836667fcaffdf2e3c6068b0a8b364dd8
- https://git.kernel.org/stable/c/996c5c19d5b5ac5b98a7b5a406b548305841c301