Impact
In the ARM System Control and Management Interface (SCMI) firmware driver, the mailbox_chan_setup routine may allocate a primary mailbox channel and then request an additional unidirectional transmit channel. If the second allocation fails, the function returns without releasing the primary channel, leaving it occupied for future probe attempts. This erroneous resource retention can cause the kernel to become unable to acquire new SCMI channels, potentially exhausting the limited mailbox pool and leading to service disruption. The flaw is a classic example of improper resource management (CWE-767) and can result in a denial‑of‑service condition for subsequent hardware or driver initialization processes.
Affected Systems
The defect resides in the Linux kernel source tree and affects all builds that compile the arm_scmi firmware driver, regardless of specific version releases. Any system running the legacy ARM SCMI implementation on Linux, including most distributions that ship a recent kernel, is potentially impacted until the driver code is updated to include the unwind fix.
Risk and Exploitability
The EPSS score is reported as less than 1%, indicating a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is most likely local: an attacker with privilege to load a malicious driver or kernel module would need to trigger the failed probe sequence to exhaust the mailbox channel resource. Although there is no remote code execution path, a successful exploitation would compromise system availability by preventing further SCMI communication, which may affect devices relying on the SCMI interface.
OpenCVE Enrichment
Debian DLA
Debian DSA