Description
In the Linux kernel, the following vulnerability has been resolved:

firmware: arm_scmi: Fix requested device removal race

scmi_protocol_device_unrequest() drops scmi_requested_devices_mtx while
notifying listeners but continues to retain the per-protocol list head.
When two SCMI drivers for the same protocol unregister concurrently, one
thread can remove the final request and free the list head while the other
is running its notifier. The latter then dereferences the freed list head
after reacquiring the mutex and can free it a second time.

Complete the list and IDR updates, including freeing an empty list head,
before dropping the mutex. Keep the blocking notifier outside the critical
section and retain only the detached request across the callback.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption leading to potential privilege escalation
Action: Immediate Patch
AI Analysis

Impact

A race condition exists in the Linux kernel firmware arm_scmi subsystem when two drivers for the same protocol unregister concurrently. The unrequest routine releases a mutex while it still holds a reference to the protocol’s request list head and then later reacquires the mutex before notifying listeners. This timing error allows a second thread to delete the final request and free the list head while the first thread is still operating on it. The result is a double free and a use‑after‑free of kernel memory, which can be leveraged by an attacker to corrupt data structures or execute arbitrary code with kernel privileges.

Affected Systems

All Linux kernel releases that include the arm_scmi driver before the patch commit identified by the Git references in the advisory. The vulnerability is present in every kernel that uses the arm_scmi interface and does not have a version restriction listed.

Risk and Exploitability

The EPSS score is less than 1% and the vulnerability is not listed in CISA's KEV catalog, indicating a low publicly observed exploitation probability. Nonetheless, the nature of the bug—double free of kernel memory—renders it high severity from a technical standpoint. Attackers would need to trigger the race by causing concurrent unregistration of SCMI drivers for the same protocol; once achieved, the resulting memory corruption could allow local privilege escalation to the kernel user ID. No public exploit code is currently available, but the possibility of an in‑kernel denial of service or arbitrary code execution exists.

Generated by OpenCVE AI on September 19, 2026 at 06:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel version that incorporates commit 1c35915eaaa81a12340c838c5c2ccb02be2194c3, which fixes the race condition in firmware arm_scmi.
  • Ensure that any compiled SCMI driver modules are updated to versions that include the protective changes described in the patch commit.
  • If an immediate kernel upgrade is unavailable, disable or prevent concurrent unregistration of SCMI drivers for the same protocol—e.g., by temporarily removing the drivers from the system or by configuring the kernel to block simultaneous unregister calls until the patch is applied.

Generated by OpenCVE AI on September 19, 2026 at 06:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CWE-415

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix requested device removal race scmi_protocol_device_unrequest() drops scmi_requested_devices_mtx while notifying listeners but continues to retain the per-protocol list head. When two SCMI drivers for the same protocol unregister concurrently, one thread can remove the final request and free the list head while the other is running its notifier. The latter then dereferences the freed list head after reacquiring the mutex and can free it a second time. Complete the list and IDR updates, including freeing an empty list head, before dropping the mutex. Keep the blocking notifier outside the critical section and retain only the detached request across the callback.
Title firmware: arm_scmi: Fix requested device removal race
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:18.067Z

Reserved: 2026-09-16T12:21:13.872Z

Link: CVE-2026-92506

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:53.187

Modified: 2026-09-17T17:17:53.187

Link: CVE-2026-92506

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T12:15:17Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-415

    Double Free