Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-64520

Опубликовано: 25 июл. 2026
Источник: nvd
CVSS3: 8.4
EPSS Низкий

Описание

In the Linux kernel, the following vulnerability has been resolved:

firmware: arm_ffa: Bound PARTITION_INFO_GET_REGS copies

The register-based PARTITION_INFO_GET path trusted the firmware-provided indices when copying partition descriptors into the caller buffer. Reject inconsistent counts or index progressions so the copy loop cannot write past the allocated array.

(fixed cur_idx when exactly one descriptor in the first fragment)

EPSS

Процентиль: 3%
0.00131
Низкий

8.4 High

CVSS3

Дефекты

Связанные уязвимости

CVSS3: 8.4
ubuntu
7 дней назад

In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Bound PARTITION_INFO_GET_REGS copies The register-based PARTITION_INFO_GET path trusted the firmware-provided indices when copying partition descriptors into the caller buffer. Reject inconsistent counts or index progressions so the copy loop cannot write past the allocated array. (fixed cur_idx when exactly one descriptor in the first fragment)

CVSS3: 7
redhat
8 дней назад

A flaw was found in the Linux kernel's ARM Firmware Framework for ARM (FFA). The PARTITION_INFO_GET_REGS function, which handles copying partition descriptors, did not adequately validate the indices provided by the firmware. This oversight could allow the system to process inconsistent data, resulting in an out-of-bounds write. Such an issue can lead to memory corruption, potentially causing system instability or a denial of service.

CVSS3: 8.4
debian
7 дней назад

In the Linux kernel, the following vulnerability has been resolved: f ...

CVSS3: 8.4
github
7 дней назад

In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Bound PARTITION_INFO_GET_REGS copies The register-based PARTITION_INFO_GET path trusted the firmware-provided indices when copying partition descriptors into the caller buffer. Reject inconsistent counts or index progressions so the copy loop cannot write past the allocated array. (fixed cur_idx when exactly one descriptor in the first fragment)

EPSS

Процентиль: 3%
0.00131
Низкий

8.4 High

CVSS3

Дефекты

Уязвимость CVE-2026-64520