Description
In the Linux kernel, the following vulnerability has been resolved:

firmware: qcom: scm: Fix NULL dereference in IRQ handler before __scm is published

In qcom_scm_probe(), devm_request_threaded_irq() is called before
smp_store_release(&__scm, scm). Two paths can dereference __scm before
it is published, both causing a NULL pointer dereference.

The IRQ handler receives scm via its data argument but passes only wq_ctx
to qcom_scm_waitq_wakeup() and qcom_scm_get_completion(), which then
dereference __scm directly. Thread scm through both functions so the IRQ
handler path never touches __scm.

Non-atomic SMC calls made during probe (e.g. from qcom_tzmem_init via
qcom_scm_shm_bridge_enable) can return WAITQ_SLEEP, causing
qcom_scm_wait_for_wq_completion() to run before __scm is published and
dereference it. Add platform_set_drvdata(pdev, scm) early in probe and
change qcom_scm_wait_for_wq_completion() to take the device pointer and
use dev_get_drvdata() to reach scm, removing any dependency on __scm.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Local Kernel Crash
Action: Apply Patch
AI Analysis

Impact

In the Linux kernel, the Qualcomm SCM driver can dereference a NULL pointer in the IRQ handler before __scm is published. This ordering bug, introduced during probe, triggers a kernel null pointer dereference. The crash leads to loss of kernel stability and can be seen as a denial‑of‑service condition for the affected system.

Affected Systems

The flaw is present in the Linux kernel’s qcom_scm implementation across all versions before the fix was applied. No specific version numbers are listed, so any kernel containing the pre‑patch driver code is potentially vulnerable.

Risk and Exploitability

The EPSS score of <1% indicates that exploitation is considered unlikely, and the vulnerability is not in the CISA KEV list. Because the fault occurs during hardware interrupt handling, it requires local physical or privileged access to trigger the IRQ, making remote exploitation improbable. An attacker with such access could force the kernel to crash, disrupting service but not gaining elevated privileges directly.

Generated by OpenCVE AI on September 19, 2026 at 05:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a version containing the fix for the qcom_scm driver.
  • If an immediate kernel upgrade is not possible, apply the upstream patch manually, recompile the kernel, and reinstall.
  • After the update, verify that no early IRQs can occur before __scm is published; review driver logs for indications of the issue.

Generated by OpenCVE AI on September 19, 2026 at 05:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: scm: Fix NULL dereference in IRQ handler before __scm is published In qcom_scm_probe(), devm_request_threaded_irq() is called before smp_store_release(&__scm, scm). Two paths can dereference __scm before it is published, both causing a NULL pointer dereference. The IRQ handler receives scm via its data argument but passes only wq_ctx to qcom_scm_waitq_wakeup() and qcom_scm_get_completion(), which then dereference __scm directly. Thread scm through both functions so the IRQ handler path never touches __scm. Non-atomic SMC calls made during probe (e.g. from qcom_tzmem_init via qcom_scm_shm_bridge_enable) can return WAITQ_SLEEP, causing qcom_scm_wait_for_wq_completion() to run before __scm is published and dereference it. Add platform_set_drvdata(pdev, scm) early in probe and change qcom_scm_wait_for_wq_completion() to take the device pointer and use dev_get_drvdata() to reach scm, removing any dependency on __scm.
Title firmware: qcom: scm: Fix NULL dereference in IRQ handler before __scm is published
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:28.967Z

Reserved: 2026-09-11T19:38:34.811Z

Link: CVE-2026-90397

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:39.417

Modified: 2026-09-17T17:17:39.417

Link: CVE-2026-90397

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T09:00:14Z

Weaknesses