Impact
A bug in the Linux kernel’s arm_scmi driver causes the mailbox channel setup routine to leave a primary channel allocated when a secondary request fails. The leftover allocation can block future probe attempts, potentially cascading into initialization failures for devices that rely on SCMI. The impact is a denial of service, manifesting as unavailable services or hung drivers during boot or runtime.
Affected Systems
The vulnerability affects Linux kernel firmware components that implement SCMI on ARM architectures. No specific kernel releases are listed in the data, so any kernel version that includes the current arm_scmi implementation may be susceptible until the fix is merged.
Risk and Exploitability
The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation in the wild. Likely attack vectors would involve local privileged access during kernel boot or firmware updates, since the flaw revolves around internal channel allocation. The risk is moderate due to its potential to disrupt device initialization but it does not enable remote code execution or other more severe attacks.
OpenCVE Enrichment
Debian DLA
Debian DSA