Executive brief
A vulnerability was identified in the Linux kernel's Arm Firmware Framework for Arm (FF-A) driver. This component manages communication between the operating system and secure firmware. An exploit could allow malformed firmware data to cause system instability or unauthorized memory access, potentially impacting the reliability and security of the device.
Technical details
A vulnerability in 'drivers/firmware/arm_ffa/driver.c' within the Linux kernel's Arm FF-A implementation resulted from insufficient validation of the offset and size fields in framework notification messages. These messages are carried in a shared RX buffer. Without proper validation, malformed firmware data could trigger an out-of-bounds read during 'kmemdup()' or UUID parsing, or cause an oversized memory allocation. The fix introduces checks to ensure the payload offset and size are within the bounds of the shared buffer and that non-header payloads start at the correct UUID field. The issue was resolved in stable branches 6.18.34, 7.0.11, and 7.1.
Affected products
- Linux Linux Kernel 6.15 to 6.18.33, 7.0 to 7.0.10
Timeline
- 2026-07-19: advisory
- 2026-06-01: patched