Out-of-bounds write in Linux kernel - CVE-2026-64520
Published: July 27, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds write in the arm ffa partition information retrieval logic in drivers/firmware/arm_ffa/driver.c when processing firmware-provided partition descriptor indices in the register-based PARTITION_INFO_GET path. A local user can provide inconsistent descriptor counts or index progressions to cause a denial of service.
Exploitation requires interaction with untrusted or malformed firmware responses.