Description
In the Linux kernel, the following vulnerability has been resolved:

firmware: arm_scmi: Unrequest devices if driver registration fails

scmi_driver_register() requests protocol devices before registering the
driver. If driver_register() fails, those requests remain in the global
IDR and retain pointers to the module's ID table. Once the failed module
load releases that storage, later request matching or SCMI device creation
can dereference the stale pointers.

Unrequest the complete protocol table before returning the registration
failure. At this point table registration succeeded, so every entry is
owned by the current registration attempt.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption
Action: Apply Patch
AI Analysis

Impact

This vulnerability exists in the ARM SCMI firmware driver of the Linux kernel. When scmi_driver_register() requests protocol devices before successful driver registration, a failure in driver_register() leaves dangling references in the global IDR. Those stale pointers point to the unloaded module’s ID table. A later SCMI operation that matches or creates a device can dereference these stale pointers, causing kernel memory corruption or a system crash. The flaw is a use‑after‑free that compromises kernel integrity and can lead to a denial of service or potential privilege escalation if exploited.

Affected Systems

Any Linux kernel that implements the generic ARM SCMI driver before the patch that removes the dangling references is affected. The specific vulnerability is tied to commits in the kernel source, notably the commit identified by 06e65e07a1bcb39a1ebc8bb89a981f8e07900497, but affected kernel versions are not enumerated in the CVE data. Users should compare their running kernel to this commit list to determine if they are impacted.

Risk and Exploitability

The EPSS score is below 1% and the vulnerability is not listed in CISA KEV, indicating a low probability of exploitation in the wild. Based on the description, it is inferred that exploiting this flaw would require the ability to load a kernel module, which typically necessitates root or CAP_SYS_MODULE privileges. Once the attacker can trigger a failed registration, the resulting use‑after‑free can corrupt kernel memory and potentially crash the system or provide a foothold for further escalation. The low EPSS score and lack of KEV listing suggest that exploitation, while technically possible, is unlikely in the current threat landscape.

Generated by OpenCVE AI on September 19, 2026 at 13:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a kernel version that includes commit 06e65e07a1bcb39a1ebc8bb89a981f8e07900497 or later, which removes the dangling references in the ARM SCMI driver.
  • If a kernel upgrade is not immediately available, blacklist or disable the ARM SCMI driver modules to prevent the failure path from executing.
  • Apply any vendor‑issued security patches that address memory‑corruption issues in the SCMI subsystem.

Generated by OpenCVE AI on September 19, 2026 at 13:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Unrequest devices if driver registration fails scmi_driver_register() requests protocol devices before registering the driver. If driver_register() fails, those requests remain in the global IDR and retain pointers to the module's ID table. Once the failed module load releases that storage, later request matching or SCMI device creation can dereference the stale pointers. Unrequest the complete protocol table before returning the registration failure. At this point table registration succeeded, so every entry is owned by the current registration attempt.
Title firmware: arm_scmi: Unrequest devices if driver registration fails
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:05.347Z

Reserved: 2026-09-16T12:21:13.871Z

Link: CVE-2026-92490

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:51.123

Modified: 2026-09-17T17:17:51.123

Link: CVE-2026-92490

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T20:15:18Z

Weaknesses