KernelScan.io

HIGH Introduced in 6.7

arm_ffa MemDescriptor OOB

CVE-2026-68400

CVSS 7.8 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

KernelScan AI8.8HIGH

01

In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset calculation Use the descriptor's `ep_mem_offset` to calculate the start of the endpoint memory access array and to comply with the FF-A spec instead of defaulting to `sizeof(struct ffa_mem_region)`. This requires moving `ffa_mem_region_additional_setup()` earlier in the setup flow. Also, add sanity checks to ensure the calculated descriptor offsets do not exceed `max_fragsize`.

02

Engine v0.6.0

Risk summary

A guest VM on an Arm platform with FF-A support can trigger out-of-bounds writes in the host kernel by initiating memory sharing transactions. The host driver miscalculates descriptor offsets and lacks bounds checks, allowing the guest to corrupt host kernel memory beyond the allocated buffer. This is a VM-to-hypervisor escape primitive with potential for arbitrary code execution on the host.

Affecteddrivers/firmware/arm_ffa/driver.c (arm_ffa firmware driver)

Vulnerability analysis

The FF-A memory sharing driver calculates the offset to endpoint memory access descriptors using a fixed structure size instead of the spec-mandated offset field stored in the descriptor itself. Because the descriptor's offset field is not initialized until later in the setup flow, the driver writes endpoint access data at incorrect positions within the transaction buffer. Combined with the absence of bounds checks on the calculated offsets against the buffer's maximum fragment size, a sufficiently large number of endpoints causes writes past the end of the allocated buffer. The fix moves the descriptor initialization earlier so the correct offset field is populated before it is read, uses that field for offset calculation, and adds overflow and bounds checks that reject transactions whose descriptor offsets would exceed the buffer size. The vulnerable code path is reached when a guest VM on an Arm system with FF-A support initiates a memory sharing or lending transaction that the host kernel processes.

03

BranchIntroducedFixed inPatch commit
6.186.76.18.42b39b08e6bee8
mainline6.77.2-rc4b4d961351aa8
7.16.77.1.68ef18f0ab3c0