{"id":"CVE-2026-64166","summary":"firmware: arm_ffa: Check for NULL FF-A ID table while driver registration","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_ffa: Check for NULL FF-A ID table while driver registration\n\nThe bus match callback assumes that every FF-A driver provides an\nid_table and dereferences it unconditionally. Enforce that contract at\nregistration time so a buggy client driver cannot crash the bus during\nmatch.","modified":"2026-07-21T03:46:54.858984964Z","published":"2026-07-19T15:40:51.305Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64166.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/0a5e695095c557d2380131b613dea4e8d90371be"},{"type":"WEB","url":"https://git.kernel.org/stable/c/198f6c86d508ed562f07dc00276cac6dbb5dd3bf"},{"type":"WEB","url":"https://git.kernel.org/stable/c/34f59211984f66788390e7469f3e99d3796db4a8"},{"type":"WEB","url":"https://git.kernel.org/stable/c/820245d86ce58898fb48b4fefc77d0cafc02801d"},{"type":"WEB","url":"https://git.kernel.org/stable/c/adfff93d08a2e12ecf2a1eba272d18bc749f13c0"},{"type":"WEB","url":"https://git.kernel.org/stable/c/bc499d1acddbb75b5b4bce05f5296dd8ef9611fd"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f98f131256beaddd51ad468e95d90d857fef12bf"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64166.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64166"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"92743071464fca5acbbe812d9a0d88de3eaaad36"},{"fixed":"f98f131256beaddd51ad468e95d90d857fef12bf"},{"fixed":"bc499d1acddbb75b5b4bce05f5296dd8ef9611fd"},{"fixed":"adfff93d08a2e12ecf2a1eba272d18bc749f13c0"},{"fixed":"34f59211984f66788390e7469f3e99d3796db4a8"},{"fixed":"820245d86ce58898fb48b4fefc77d0cafc02801d"},{"fixed":"198f6c86d508ed562f07dc00276cac6dbb5dd3bf"},{"fixed":"0a5e695095c557d2380131b613dea4e8d90371be"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64166.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.14.0"},{"fixed":"5.15.209"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.175"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.142"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.92"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.34"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.0.11"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64166.json"}}],"schema_version":"1.7.5"}