Impact
This vulnerability exists in the ARM SCMI firmware driver of the Linux kernel. When scmi_driver_register() requests protocol devices before successful driver registration, a failure in driver_register() leaves dangling references in the global IDR. Those stale pointers point to the unloaded module’s ID table. A later SCMI operation that matches or creates a device can dereference these stale pointers, causing kernel memory corruption or a system crash. The flaw is a use‑after‑free that compromises kernel integrity and can lead to a denial of service or potential privilege escalation if exploited.
Affected Systems
Any Linux kernel that implements the generic ARM SCMI driver before the patch that removes the dangling references is affected. The specific vulnerability is tied to commits in the kernel source, notably the commit identified by 06e65e07a1bcb39a1ebc8bb89a981f8e07900497, but affected kernel versions are not enumerated in the CVE data. Users should compare their running kernel to this commit list to determine if they are impacted.
Risk and Exploitability
The EPSS score is below 1% and the vulnerability is not listed in CISA KEV, indicating a low probability of exploitation in the wild. Based on the description, it is inferred that exploiting this flaw would require the ability to load a kernel module, which typically necessitates root or CAP_SYS_MODULE privileges. Once the attacker can trigger a failed registration, the resulting use‑after‑free can corrupt kernel memory and potentially crash the system or provide a foothold for further escalation. The low EPSS score and lack of KEV listing suggest that exploitation, while technically possible, is unlikely in the current threat landscape.
OpenCVE Enrichment
Debian DLA
Debian DSA