---
id: CVE-2026-64080
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  firmware: arm_ffa: Snapshot notifier callbacks under lock

  Both notification handlers currently look up a notifier callback under
  notify_lock, drop the lock, and then d…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  firmware: arm_ffa: Snapshot notifier callbacks under lock

  Both notification handlers currently look up a notifier callback under
  notify_lock, drop the lock, and then d…
severity: critical
cvss: 9.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-416
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 6.15, < 6.18.34'
  - 'linux_kernel >= 6.19, < 7.0.11'
  - linux_kernel = 7.1
patched:
  - linux_kernel 7.0.11
published: '2026-07-19'
updated: '2026-09-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-64080'
references:
  - url: 'https://git.kernel.org/stable/c/0e7be42ef2490f19d859a6146324d48cafdc9d5c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/38290b180a4d5746baed796d49f88d56d2f336cd'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d1e38551fadea230649bc428f0f35c9ee062a072'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00145
epssPercentile: 0.04181
ingestedAt: '2026-09-04T05:15:22.965Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

firmware: arm_ffa: Snapshot notifier callbacks under lock

Both notification handlers currently look up a notifier callback under
notify_lock, drop the lock, and then dereference the returned
notifier entry. A concurrent unregister can delete and free that
entry in the gap, leaving the handler to dereference stale memory.

Copy the callback pointer and callback data while notify_lock is
still held and invoke the callback only after the lock is dropped.
This keeps the existing callback execution model while removing the
use-after-free window in both the framework and non-framework
notification paths.

## Affected

- `linux_kernel >= 6.15, < 6.18.34`
- `linux_kernel >= 6.19, < 7.0.11`
- `linux_kernel = 7.1`

## Remediation

Upgrade past the affected range:

- `linux_kernel 7.0.11`
