Description
In the Linux kernel, the following vulnerability has been resolved:

firmware: arm_scmi: Roll back partial protocol table registration

scmi_protocol_table_register() can leave earlier requests registered when
a later entry in the same ID table fails. Each request retains a pointer
to the driver's ID table, so a failed module load can leave a dangling
pointer after the module storage is released.

Unrequest only the successfully registered prefix, in reverse order,
before returning the failure. Leave the failed entry and the remaining
entries untouched because matching requests can be owned by another
driver.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Memory corruption
Action: Patch
AI Analysis

Impact

The vulnerability originates from the scmi_protocol_table_register function in the Linux kernel's ARM SCMI driver. When a later entry in the same ID table fails, the function can leave earlier successful requests registered while keeping references to the driver's ID table. If the module storage is released, these references become dangling pointers, leading to a use‑after‑free condition. This flaw can cause memory corruption or crash the kernel, potentially leading to denial of service. The weakness corresponds to use‑after‑free (CWE‑416).

Affected Systems

The affected product is the Linux kernel, specifically the ARM SCMI implementation used for secure communication between processor cores. No specific kernel version is listed as affected by the CVE, so all kernel releases that include the unpatched ARM SCMI firmware interface are potentially vulnerable. This includes all distributions and vendors that ship the kernel with the ARM SCMI driver without the patch that removes the partial registration issue.

Risk and Exploitability

The EPSS score is reported to be less than 1 %, indicating a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploits at this time. The flaw requires the ability to load or interact with ARM SCMI drivers that register protocol tables, which typically requires kernel‑level privileges or the presence of a malicious or buggy driver. Thus, exploitation is likely limited to privileged or compromised environments. The risk is considered moderate, with the primary threat being potential denial of service via kernel crash, but the likelihood of a successful exploit remains low.

Generated by OpenCVE AI on September 19, 2026 at 09:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the patch for scmi_protocol_table_register (commit 2023‑12‑02 or later) to remove partial registration handling.
  • As an interim measure, prevent loading of custom or unsigned ARM SCMI drivers that register protocol tables, or configure the kernel to restrict module loading for that driver.
  • Monitor kernel release notes, vendor advisories, or the Linux kernel mailing list for updates or additional workarounds related to the ARM SCMI interface.

Generated by OpenCVE AI on September 19, 2026 at 09:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Roll back partial protocol table registration scmi_protocol_table_register() can leave earlier requests registered when a later entry in the same ID table fails. Each request retains a pointer to the driver's ID table, so a failed module load can leave a dangling pointer after the module storage is released. Unrequest only the successfully registered prefix, in reverse order, before returning the failure. Leave the failed entry and the remaining entries untouched because matching requests can be owned by another driver.
Title firmware: arm_scmi: Roll back partial protocol table registration
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:06.627Z

Reserved: 2026-09-16T12:21:13.871Z

Link: CVE-2026-92491

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:51.233

Modified: 2026-09-17T17:17:51.233

Link: CVE-2026-92491

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T11:15:13Z

Weaknesses