PT-2026-61397 · Linux · Linux

CVE-2026-64080

·

Published

2026-07-19

·

Updated

2026-07-19

CVSS v3.1

9.3

Critical

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
In the Linux kernel, the following vulnerability has been resolved:
firmware: arm ffa: Snapshot notifier callbacks under lock
Both notification handlers currently look up a notifier callback under notify lock, drop the lock, and then dereference the returned notifier entry. A concurrent unregister can delete and free that entry in the gap, leaving the handler to dereference stale memory.
Copy the callback pointer and callback data while notify lock is still held and invoke the callback only after the lock is dropped. This keeps the existing callback execution model while removing the use-after-free window in both the framework and non-framework notification paths.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-64080

Affected Products

Linux