Description
In the Linux kernel, the following vulnerability has been resolved:

firmware: arm_scmi: Fix SCMI device destroy lifetimes

scmi_child_dev_find() drops the reference returned by
device_find_child() before returning the scmi_device pointer. A
concurrent unregister can then release the device while the destroy path
is still using the returned pointer.

Make the lookup helper return the device_find_child() reference and keep
it until scmi_device_destroy() has finished unregistering the child.

Also split device_unregister() in __scmi_device_destroy() so the SCMI bus
ID is not made reusable until after device_del() has removed the old
scmi_dev.N name from sysfs. This avoids a new SCMI device reusing the
same ID while the old device is still registered.

The final device release callback is also a possible cleanup path when
SCMI children are deleted by driver core recursion rather than
__scmi_device_destroy(). Release the SCMI bus ID from a common helper
used by destroy, register-failure and final-release paths, and clear
scmi_dev->id after freeing it so the final release cannot free the same
ID again.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use-After-Free leading to memory corruption
Action: Immediate Patch
AI Analysis

Impact

The kernel’s SCMI child device lookup released a reference too early, allowing a concurrent unregister to free the device while the destroy path was still using it. This race can cause a use‑after‑free of the device structure, leading to kernel memory corruption. The subsequent splitting of the unregister sequence and clear of the bus ID further mitigates the reuse issue, but the fix is required to prevent the flaw.

Affected Systems

All releases of the Linux kernel that include the ARM SCMI driver. The bug was present before any support for the latest stable and long‑term releases, and should be considered pervasive across distributions that ship the stock kernel.

Risk and Exploitability

The EPSS score is reported as less than 1%, suggesting low current exploitation probability. The flaw is not listed in the CISA KEV catalog. The CVSS score is not provided in the data, but the nature of the bug suggests a high severity. Attackers with the ability to trigger a concurrent unregister of an SCMI child device could achieve memory corruption, potentially resulting in a denial of service or privilege escalation. The primary attack vector is through the SCMI bus interface, which is typically available to privileged kernel components or privileged users with device access.

Generated by OpenCVE AI on September 19, 2026 at 06:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that incorporates the fix from commit 6abe8fe and c59b3393.
  • If unable to upgrade immediately, disable or remove the ARM SCMI driver by blacklisting the module or disabling the corresponding platform device.
  • If the device must remain active, limit access by tightening udev rules or isolating the device within a container or unprivileged context.

Generated by OpenCVE AI on September 19, 2026 at 06:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
CWE-665

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix SCMI device destroy lifetimes scmi_child_dev_find() drops the reference returned by device_find_child() before returning the scmi_device pointer. A concurrent unregister can then release the device while the destroy path is still using the returned pointer. Make the lookup helper return the device_find_child() reference and keep it until scmi_device_destroy() has finished unregistering the child. Also split device_unregister() in __scmi_device_destroy() so the SCMI bus ID is not made reusable until after device_del() has removed the old scmi_dev.N name from sysfs. This avoids a new SCMI device reusing the same ID while the old device is still registered. The final device release callback is also a possible cleanup path when SCMI children are deleted by driver core recursion rather than __scmi_device_destroy(). Release the SCMI bus ID from a common helper used by destroy, register-failure and final-release paths, and clear scmi_dev->id after freeing it so the final release cannot free the same ID again.
Title firmware: arm_scmi: Fix SCMI device destroy lifetimes
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:01.679Z

Reserved: 2026-09-17T15:57:05.662Z

Link: CVE-2026-93081

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:02.063

Modified: 2026-09-17T17:18:02.063

Link: CVE-2026-93081

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T17:00:11Z

Weaknesses