CVE-2026-68444: firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get()
In the Linux kernel, the following vulnerability has been resolved:
firmware: armffa: Fix NULL dereference in ffapartitioninfoget()
ffapartitioninfoget() passes uuidstr directly to uuidparse() without a NULL check. When a caller passes NULL, uuidparse() -> uuidparse() -> uuidisvalid() dereferences the pointer, causing a kernel panic:
| Unable to handle kernel NULL pointer dereference at virtual address | 0000000000000040 | pc : uuidparse+0x40/0xac | lr : ffapartitioninfoget+0x1c/0x94 [armffa]
Add a NULL guard before uuidparse() so a NULL argument returns -ENODEV instead of crashing. Callers are expected to always supply a valid partition UUID, so NULL is not a supported input.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
firmware: arm_ffato a version that resolves this vulnerability.Patch Fix NULL dereference in ffa_partition_info_get()
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68444?
CVE-2026-68444 has a risk score of 34.
How do I fix CVE-2026-68444?
To fix CVE-2026-68444, update your Linux kernel to the latest patched version.
What type of vulnerability is CVE-2026-68444?
CVE-2026-68444 is categorized as a Null Pointer Dereference vulnerability.
What happens if I am affected by CVE-2026-68444?
If affected by CVE-2026-68444, a NULL dereference could lead to a system crash or instability.
In which version of the Linux kernel was CVE-2026-68444 resolved?
CVE-2026-68444 was resolved in a stable release of the Linux kernel.