AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-68400

HIGH · CVSS 7.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A vulnerability in the Linux kernel affects the firmware component responsible for managing memory access descriptors in ARM systems. The flaw could lead to improper calculations of memory access offsets, potentially allowing unauthorized access to memory regions, which may compromise system integrity. Organizations using affected Linux distributions, particularly those deploying ARM architecture, should prioritize applying the fix to mitigate potential security risks.

CVE
CVE-2026-68400
Severity
HIGH
CVSS
7.8
EPSS
0.13%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset calculation Use the descriptor's `ep_mem_offset` to calculate the start of the endpoint memory access array and to comply with the FF-A spec instead of defaulting to `sizeof(struct ffa_mem_region)`. This requires moving `ffa_mem_region_additional_setup()` earlier in the setup flow. Also, add sanity checks to ensure the calculated descriptor offsets do not exceed `max_fragsize`.