{"api_version":"1","generated_at":"2026-08-14T04:35:38+00:00","cve":"CVE-2026-68400","urls":{"html":"https://cve.report/CVE-2026-68400","api":"https://cve.report/api/cve/CVE-2026-68400.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-68400","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-68400"},"summary":{"title":"firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset calculation","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset calculation\n\nUse the descriptor's `ep_mem_offset` to calculate the start of the endpoint\nmemory access array and to comply with the FF-A spec instead of defaulting\nto `sizeof(struct ffa_mem_region)`.\nThis requires moving `ffa_mem_region_additional_setup()` earlier in the setup\nflow.\nAlso, add sanity checks to ensure the calculated descriptor offsets do not\nexceed `max_fragsize`.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-10 13:20:33","updated_at":"2026-08-13 23:17:35"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/b39b08e6bee812514b449dc874076890e6b871a0","name":"https://git.kernel.org/stable/c/b39b08e6bee812514b449dc874076890e6b871a0","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/b4d961351aa84fdf0148783fb1f3a1391b8a0adb","name":"https://git.kernel.org/stable/c/b4d961351aa84fdf0148783fb1f3a1391b8a0adb","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/8ef18f0ab3c0ec1eac77289f5a542bd96a8a6d66","name":"https://git.kernel.org/stable/c/8ef18f0ab3c0ec1eac77289f5a542bd96a8a6d66","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-68400","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68400","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 113580530ee7dc61e668b641d657920734533b9f b39b08e6bee812514b449dc874076890e6b871a0 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 113580530ee7dc61e668b641d657920734533b9f 8ef18f0ab3c0ec1eac77289f5a542bd96a8a6d66 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 113580530ee7dc61e668b641d657920734533b9f b4d961351aa84fdf0148783fb1f3a1391b8a0adb git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.7","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.7 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.42 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.6 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2-rc4 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"68400","cve":"CVE-2026-68400","epss":"0.001660000","percentile":"0.062280000","score_date":"2026-08-13","updated_at":"2026-08-14 00:07:35"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/firmware/arm_ffa/driver.c","include/linux/arm_ffa.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"b39b08e6bee812514b449dc874076890e6b871a0","status":"affected","version":"113580530ee7dc61e668b641d657920734533b9f","versionType":"git"},{"lessThan":"8ef18f0ab3c0ec1eac77289f5a542bd96a8a6d66","status":"affected","version":"113580530ee7dc61e668b641d657920734533b9f","versionType":"git"},{"lessThan":"b4d961351aa84fdf0148783fb1f3a1391b8a0adb","status":"affected","version":"113580530ee7dc61e668b641d657920734533b9f","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/firmware/arm_ffa/driver.c","include/linux/arm_ffa.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.7"},{"lessThan":"6.7","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.42","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.6","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2-rc4","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.42","versionStartIncluding":"6.7","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.6","versionStartIncluding":"6.7","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2-rc4","versionStartIncluding":"6.7","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset calculation\n\nUse the descriptor's `ep_mem_offset` to calculate the start of the endpoint\nmemory access array and to comply with the FF-A spec instead of defaulting\nto `sizeof(struct ffa_mem_region)`.\nThis requires moving `ffa_mem_region_additional_setup()` earlier in the setup\nflow.\nAlso, add sanity checks to ensure the calculated descriptor offsets do not\nexceed `max_fragsize`."}],"metrics":[{"cvssV3_1":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - The vulnerable FF-A memory-descriptor setup is reached only through local kernel interfaces — TEE device ioctls (/dev/tee*) driving optee/tstee shared-memory registration and lend paths, or host-side FF-A SMC handling. No network or remote packet input reaches this code.\nAC:L - The out-of-bounds descriptor writes follow deterministically from the endpoint count and offsets used to build the transaction; no race, no memory-layout luck, and no condition outside the attacker's influence is needed to drive the unvalidated offset arithmetic past max_fragsize.\nPR:L - An unprivileged local process holding a handle to the TEE device node (common on Android/embedded ARM systems, where TEE clients are ordinary user processes) can drive ffa_setup_and_transmit() via shared-memory registration/lend operations; no root or capability check gates that path.\nUI:N - The vulnerable path is entered directly from the attacker's own ioctl/FF-A operations; no action by another user or administrator is required.\nS:U - The out-of-bounds writes corrupt kernel memory adjacent to the FF-A TX buffer within the same kernel security authority, so impact is scored as Unchanged even though the same offset confusion also feeds the pKVM/secure-world descriptor parsing.\nC:H - Descriptor offsets computed without validation against max_fragsize let structured data be placed and read back outside the intended buffer, and the resulting heap corruption is leverageable into disclosure of adjacent kernel memory, including data later handed to the secure world.\nI:H - This is an out-of-bounds write of attacker-influenced endpoint descriptor fields (receiver, attrs, composite_off, impdef values) plus a memset past the end of the TX buffer, giving heap corruption that can be groomed into a control-flow or data-structure overwrite primitive.\nA:H - Writing endpoint memory access descriptors beyond the RX/TX buffer corrupts unrelated kernel allocations and readily produces an oops or panic, and the mis-parsed descriptor can also drive the memory transaction into an inconsistent state with the secure partition."}]}],"providerMetadata":{"dateUpdated":"2026-08-13T22:44:34.226Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/b39b08e6bee812514b449dc874076890e6b871a0"},{"url":"https://git.kernel.org/stable/c/8ef18f0ab3c0ec1eac77289f5a542bd96a8a6d66"},{"url":"https://git.kernel.org/stable/c/b4d961351aa84fdf0148783fb1f3a1391b8a0adb"}],"title":"firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset calculation","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-68400","datePublished":"2026-08-10T12:04:19.952Z","dateReserved":"2026-07-30T09:28:09.389Z","dateUpdated":"2026-08-13T22:44:34.226Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-10 13:20:33","lastModifiedDate":"2026-08-13 23:17:35","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"68400","Ordinal":"1","Title":"firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset ","CVE":"CVE-2026-68400","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"68400","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset calculation\n\nUse the descriptor's `ep_mem_offset` to calculate the start of the endpoint\nmemory access array and to comply with the FF-A spec instead of defaulting\nto `sizeof(struct ffa_mem_region)`.\nThis requires moving `ffa_mem_region_additional_setup()` earlier in the setup\nflow.\nAlso, add sanity checks to ensure the calculated descriptor offsets do not\nexceed `max_fragsize`.","Type":"Description","Title":"firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset "}]}}}