Impact
The kernel’s SCMI child device lookup released a reference too early, allowing a concurrent unregister to free the device while the destroy path was still using it. This race can cause a use‑after‑free of the device structure, leading to kernel memory corruption. The subsequent splitting of the unregister sequence and clear of the bus ID further mitigates the reuse issue, but the fix is required to prevent the flaw.
Affected Systems
All releases of the Linux kernel that include the ARM SCMI driver. The bug was present before any support for the latest stable and long‑term releases, and should be considered pervasive across distributions that ship the stock kernel.
Risk and Exploitability
The EPSS score is reported as less than 1%, suggesting low current exploitation probability. The flaw is not listed in the CISA KEV catalog. The CVSS score is not provided in the data, but the nature of the bug suggests a high severity. Attackers with the ability to trigger a concurrent unregister of an SCMI child device could achieve memory corruption, potentially resulting in a denial of service or privilege escalation. The primary attack vector is through the SCMI bus interface, which is typically available to privileged kernel components or privileged users with device access.
OpenCVE Enrichment