In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix OOB in scmi_power_name_get() scmi_power_name_get() does not validate the domain number passed by the external caller, which may lead to an out-of-bounds access. Fix this by returning "unknown" for invalid domains, like scmi_reset_name_get() does.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-80649 is an out-of-bounds (OOB) memory access vulnerability in the Linux kernel's ARM SCMI (System Control and Management Interface) firmware driver, specifically in the scmi_power_name_get() function. The vulnerability stems from insufficient input validation when external callers pass domain numbers to this function, potentially allowing attackers to read or manipulate memory beyond intended boundaries. This affects systems running vulnerable Linux kernels with ARM SCMI support enabled, including embedded devices, IoT systems, and ARM-based servers that rely on firmware management interfaces. The vulnerability carries a CVSS score of 7.8 (high severity), indicating significant risk to system integrity and confidentiality.
While Casky.ai currently shows zero matching skills for this specific CVE, practitioners using Claude AI-powered analysis would look for detection patterns associated with memory access anomalies and firmware-level exploitation techniques. In a mature MITRE ATT&CK mapping framework, this vulnerability aligns with techniques like T1006 (Direct Kernel Object Manipulation) and T1187 (Forced Authentication) for firmware exploitation scenarios. A practitioner analyzing this threat would examine kernel logs for unexpected domain enumeration attempts, memory access patterns that deviate from normal SCMI operations, and firmware driver crash dumps indicating boundary violations. As Casky expands its 754 security skills database with enhanced Claude reasoning, defenders would gain capabilities to correlate OOB access patterns with pre-exploitation reconnaissance and identify attempts to probe SCMI driver boundaries before launching full attacks.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-80649. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation