CVE-2026-64080
A flaw in the Linux kernel's firmware management for ARM systems allows for a memory error. This occurs because the system releases a security lock before it finishes using a specific piece of data, creating a window where that data can be deleted while still being accessed.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users running the Linux kernel with arm_ffa firmware support.
Real-world impact
An attacker could potentially exploit this memory error to cause a system crash or execute unauthorized code by manipulating the data being accessed during the vulnerability window.
Why this severity
The critical score reflects that an attacker can achieve a complete loss of confidentiality, integrity, and availability by exploiting a race condition in the kernel.
What to do about it
- 01Update the Linux kernel to the version containing the fix for the arm_ffa snapshot notifier callbacks.
NVD-referenced vendor advisory
Timeline
- Jul 19, 2026 · 14d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 13d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 30, 2026 · 3d agoAdvisory updatedThe NVD record was last revised.