GHSA-3fjr-pmvp-g6q5HighCVSS 8.2

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Check the...

Published
December 4, 2025
Last Modified
July 30, 2026

🔗 CVE IDs covered (1)

📋 Description

In the Linux kernel, the following vulnerability has been resolved:

KVM: arm64: Check the untrusted offset in FF-A memory share

Verify the offset to prevent OOB access in the hypervisor FF-A buffer in case an untrusted large enough value [U32_MAX - sizeof(struct ffa_composite_mem_region) + 1, U32_MAX] is set from the host kernel.

🔗 References (6)