Description
In the Linux kernel, the following vulnerability has been resolved:

firmware: arm_scmi: Fix transport device teardown lookup

SCMI transport devices are deliberately excluded from normal SCMI bus
matching so protocol drivers cannot bind to the internal transport
children. However, scmi_device_destroy() uses the same protocol/name
lookup to find devices that must be unregistered during channel teardown.

Split the match helper so driver matching still skips transport devices,
while explicit child lookup can find them for teardown. Use a shared
transport-device name prefix macro for both matching and name generation.

Since transport-device names are derived from direction and protocol ID,
reject duplicate protocol channel setup before creating or finding a
transport device. This prevents malformed firmware with duplicate
protocol child nodes from reusing an existing transport device and then
destroying it when the duplicate IDR insertion fails.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Potential Kernel Crash
Action: Apply patch
AI Analysis

Impact

This bug in the SCMI transport subsystem causes the kernel to incorrectly match transport devices when destroying SCMI children. If duplicate protocol channel entries are present, the kernel attempts to reuse an existing transport device and then later destroys it when the duplicate IDR insertion fails. This improper teardown can lead to the removal of an already‑registered device and may destabilize the kernel, potentially resulting in a crash.

Affected Systems

All Linux kernel releases that include SCMI support prior to the application of the fix. The vulnerability is present in the generic Linux kernel on all vendors that ship it (Linux:Linux). No specific kernel version ranges are listed; the affected code is the SCMI transport layer.

Risk and Exploitability

The EPSS score is below 1%, indicating a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, and no CVSS score is provided in the data. Exploitation would likely require a user to supply malformed firmware or privileged access to modify SCMI child nodes, making it a local‑level, firmware‑based attack vector.

Generated by OpenCVE AI on September 19, 2026 at 06:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel release that contains the SCMI transport device teardown fix (commit 4635953b4c1af477e166073521a77de6279f6929 or later).
  • Rebuild or modify any custom firmware loaded for SCMI devices to ensure it does not declare duplicate protocol child nodes, thereby preventing the IDR insertion failure scenario.
  • After updating the kernel and firmware, restart the system and monitor kernel logs for scmi_device_destroy or related errors to confirm that the teardown process functions correctly.

Generated by OpenCVE AI on September 19, 2026 at 06:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix transport device teardown lookup SCMI transport devices are deliberately excluded from normal SCMI bus matching so protocol drivers cannot bind to the internal transport children. However, scmi_device_destroy() uses the same protocol/name lookup to find devices that must be unregistered during channel teardown. Split the match helper so driver matching still skips transport devices, while explicit child lookup can find them for teardown. Use a shared transport-device name prefix macro for both matching and name generation. Since transport-device names are derived from direction and protocol ID, reject duplicate protocol channel setup before creating or finding a transport device. This prevents malformed firmware with duplicate protocol child nodes from reusing an existing transport device and then destroying it when the duplicate IDR insertion fails.
Title firmware: arm_scmi: Fix transport device teardown lookup
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:01.005Z

Reserved: 2026-09-17T15:57:05.662Z

Link: CVE-2026-93080

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:01.950

Modified: 2026-09-17T17:18:01.950

Link: CVE-2026-93080

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T14:00:14Z

Weaknesses