Description
In the Linux kernel, the following vulnerability has been resolved:

firmware: arm_scmi: Unwind P2A receiver mailbox setup failure

mailbox_chan_setup() can request an additional P2A receiver channel after
successfully acquiring the primary P2A channel. If that later request
fails, the function returns immediately and leaves the primary channel
allocated.

Unwind the primary mailbox channel before returning the error so probe
deferral or other setup failures do not leave the channel busy for later
probe attempts.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply patch
AI Analysis

Impact

A bug in the Linux kernel’s arm_scmi driver causes the mailbox channel setup routine to leave a primary channel allocated when a secondary request fails. The leftover allocation can block future probe attempts, potentially cascading into initialization failures for devices that rely on SCMI. The impact is a denial of service, manifesting as unavailable services or hung drivers during boot or runtime.

Affected Systems

The vulnerability affects Linux kernel firmware components that implement SCMI on ARM architectures. No specific kernel releases are listed in the data, so any kernel version that includes the current arm_scmi implementation may be susceptible until the fix is merged.

Risk and Exploitability

The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation in the wild. Likely attack vectors would involve local privileged access during kernel boot or firmware updates, since the flaw revolves around internal channel allocation. The risk is moderate due to its potential to disrupt device initialization but it does not enable remote code execution or other more severe attacks.

Generated by OpenCVE AI on September 19, 2026 at 07:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that fixes the pouch channel cleanup issue for arm_scmi drivers
  • Restart the system to ensure the new kernel is running and the channel allocation state is cleared
  • If an immediate kernel update is not available, isolate or disable ARM‑SCMI based firmware that requires the affected channel setup until a fix can be applied

Generated by OpenCVE AI on September 19, 2026 at 07:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-664

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Unwind P2A receiver mailbox setup failure mailbox_chan_setup() can request an additional P2A receiver channel after successfully acquiring the primary P2A channel. If that later request fails, the function returns immediately and leaves the primary channel allocated. Unwind the primary mailbox channel before returning the error so probe deferral or other setup failures do not leave the channel busy for later probe attempts.
Title firmware: arm_scmi: Unwind P2A receiver mailbox setup failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:02.339Z

Reserved: 2026-09-17T15:57:05.662Z

Link: CVE-2026-93082

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:02.193

Modified: 2026-09-17T17:18:02.193

Link: CVE-2026-93082

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T14:15:17Z

Weaknesses
  • CWE-664

    Improper Control of a Resource Through its Lifetime