Junglewise Threat Intelligence

CVE-2026-64080: Linux Kernel use-after-free in ARM FF-A firmware driver

CVE-2026-64080 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's ARM Firmware Framework (FF-A) driver that could lead to a system crash. The issue occurs when the system attempts to process notifications while a driver is being unregistered, potentially leading to the use of invalid memory. This could impact system stability and availability on ARM-based systems using this specific firmware interface.

Technical details

A use-after-free (UAF) vulnerability exists in drivers/firmware/arm_ffa/driver.c within the Linux kernel. The root cause is a race condition where notification handlers (handle_notif_callbacks and handle_fwk_notif_callbacks) look up a notifier callback under notify_lock, drop the lock, and then dereference the returned entry. If a concurrent unregister operation occurs during this window, the entry may be freed, leading to a dereference of stale memory. The fix involves snapshotting the callback pointer and data while the lock is still held. This affects ARM-based systems utilizing the FF-A (Firmware Framework for Arm A-profile) for secure-world communication.

Affected products

  • Linux Linux Kernel 6.15 to 6.18.33, 7.0.10

Timeline

  • 2026-04-28: other: Patch authored
  • 2026-07-19: disclosed: CVE published

References

Related threats