CVE-2026-64080

Source
https://cve.org/CVERecord?id=CVE-2026-64080
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64080.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64080
Downstream
Published
2026-07-19T15:39:52.818Z
Modified
2026-07-22T05:30:04.677710231Z
Severity
  • 9.3 (Critical) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
firmware: arm_ffa: Snapshot notifier callbacks under lock
Details

In the Linux kernel, the following vulnerability has been resolved:

firmware: arm_ffa: Snapshot notifier callbacks under lock

Both notification handlers currently look up a notifier callback under notify_lock, drop the lock, and then dereference the returned notifier entry. A concurrent unregister can delete and free that entry in the gap, leaving the handler to dereference stale memory.

Copy the callback pointer and callback data while notify_lock is still held and invoke the callback only after the lock is dropped. This keeps the existing callback execution model while removing the use-after-free window in both the framework and non-framework notification paths.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64080.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
285a5ea0f542db94c3ed11e01a71abb47d15cbf5
Fixed
d1e38551fadea230649bc428f0f35c9ee062a072
Fixed
0e7be42ef2490f19d859a6146324d48cafdc9d5c
Fixed
38290b180a4d5746baed796d49f88d56d2f336cd

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64080.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.15.0
Fixed
6.18.34
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.11

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64080.json"