CVE-2026-64080
Critical · CVSS 9.3- CVSS
- 9.3
- nvd
- EPSS
- 0.18%
- 8th pct
- KEV
- No
- Class
- oss containerizable
Description
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Snapshot notifier callbacks under lock Both notification handlers currently look up a notifier callback under notify_lock, drop the lock, and then dereference the returned notifier entry. A concurrent unregister can delete and free that entry in the gap, leaving the handler to dereference stale memory. Copy the callback pointer and callback data while notify_lock is still held and invoke the callback only after the lock is dropped. This keeps the existing callback execution model while removing the use-after-free window in both the framework and non-framework notification paths.
Affected packages
| Linux | Kernel | 6.15.0 → 6.18.34 |
| Linux | Kernel | 6.19.0 → 7.0.11 |
References
Status: profiled · ingested 2026-07-20T18:00:18.000Z