Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9fc3-h9fc-q4xw

Опубликовано: 10 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

In the Linux kernel, the following vulnerability has been resolved:

firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset calculation

Use the descriptor's ep_mem_offset to calculate the start of the endpoint memory access array and to comply with the FF-A spec instead of defaulting to sizeof(struct ffa_mem_region). This requires moving ffa_mem_region_additional_setup() earlier in the setup flow. Also, add sanity checks to ensure the calculated descriptor offsets do not exceed max_fragsize.

In the Linux kernel, the following vulnerability has been resolved:

firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset calculation

Use the descriptor's ep_mem_offset to calculate the start of the endpoint memory access array and to comply with the FF-A spec instead of defaulting to sizeof(struct ffa_mem_region). This requires moving ffa_mem_region_additional_setup() earlier in the setup flow. Also, add sanity checks to ensure the calculated descriptor offsets do not exceed max_fragsize.

EPSS

Процентиль: 3%
0.00127
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
22 дня назад

In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset calculation Use the descriptor's `ep_mem_offset` to calculate the start of the endpoint memory access array and to comply with the FF-A spec instead of defaulting to `sizeof(struct ffa_mem_region)`. This requires moving `ffa_mem_region_additional_setup()` earlier in the setup flow. Also, add sanity checks to ensure the calculated descriptor offsets do not exceed `max_fragsize`.

CVSS3: 7
redhat
22 дня назад

In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset calculation Use the descriptor's `ep_mem_offset` to calculate the start of the endpoint memory access array and to comply with the FF-A spec instead of defaulting to `sizeof(struct ffa_mem_region)`. This requires moving `ffa_mem_region_additional_setup()` earlier in the setup flow. Also, add sanity checks to ensure the calculated descriptor offsets do not exceed `max_fragsize`.

CVSS3: 7.8
nvd
22 дня назад

In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset calculation Use the descriptor's `ep_mem_offset` to calculate the start of the endpoint memory access array and to comply with the FF-A spec instead of defaulting to `sizeof(struct ffa_mem_region)`. This requires moving `ffa_mem_region_additional_setup()` earlier in the setup flow. Also, add sanity checks to ensure the calculated descriptor offsets do not exceed `max_fragsize`.

CVSS3: 7.8
debian
22 дня назад

In the Linux kernel, the following vulnerability has been resolved: f ...

EPSS

Процентиль: 3%
0.00127
Низкий

7.8 High

CVSS3