Impact
A race condition exists in the Linux kernel firmware arm_scmi subsystem when two drivers for the same protocol unregister concurrently. The unrequest routine releases a mutex while it still holds a reference to the protocol’s request list head and then later reacquires the mutex before notifying listeners. This timing error allows a second thread to delete the final request and free the list head while the first thread is still operating on it. The result is a double free and a use‑after‑free of kernel memory, which can be leveraged by an attacker to corrupt data structures or execute arbitrary code with kernel privileges.
Affected Systems
All Linux kernel releases that include the arm_scmi driver before the patch commit identified by the Git references in the advisory. The vulnerability is present in every kernel that uses the arm_scmi interface and does not have a version restriction listed.
Risk and Exploitability
The EPSS score is less than 1% and the vulnerability is not listed in CISA's KEV catalog, indicating a low publicly observed exploitation probability. Nonetheless, the nature of the bug—double free of kernel memory—renders it high severity from a technical standpoint. Attackers would need to trigger the race by causing concurrent unregistration of SCMI drivers for the same protocol; once achieved, the resulting memory corruption could allow local privilege escalation to the kernel user ID. No public exploit code is currently available, but the possibility of an in‑kernel denial of service or arbitrary code execution exists.
OpenCVE Enrichment
Debian DLA
Debian DSA