In the Linux kernel, the following vulnerability has been resolved:
firmware: armffa: Fix NULL dereference in ffapartitioninfoget()
ffapartitioninfoget() passes uuidstr directly to uuidparse() without a NULL check. When a caller passes NULL, uuidparse() -> _uuidparse() -> uuidisvalid() dereferences the pointer, causing a kernel panic:
| Unable to handle kernel NULL pointer dereference at virtual address | 0000000000000040 | pc : uuidparse+0x40/0xac | lr : ffapartitioninfoget+0x1c/0x94 [arm_ffa]
Add a NULL guard before uuid_parse() so a NULL argument returns -ENODEV instead of crashing. Callers are expected to always supply a valid partition UUID, so NULL is not a supported input.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68444.json",
"cna_assigner": "Linux"
}