Description
In the Linux kernel, the following vulnerability has been resolved:

firmware: arm_scmi: Unwind TX receiver mailbox setup failure

mailbox_chan_setup() can request an additional unidirectional TX
receiver channel after successfully acquiring the primary channel. If
that second request fails, the function returns immediately and leaves
the primary channel allocated.

Unwind the primary mailbox channel before returning the error so probe
deferral or other setup failures do not leave the channel busy for later
probe attempts.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Resource Exhaustion
Action: Immediate Patch
AI Analysis

Impact

In the ARM System Control and Management Interface (SCMI) firmware driver, the mailbox_chan_setup routine may allocate a primary mailbox channel and then request an additional unidirectional transmit channel. If the second allocation fails, the function returns without releasing the primary channel, leaving it occupied for future probe attempts. This erroneous resource retention can cause the kernel to become unable to acquire new SCMI channels, potentially exhausting the limited mailbox pool and leading to service disruption. The flaw is a classic example of improper resource management (CWE-767) and can result in a denial‑of‑service condition for subsequent hardware or driver initialization processes.

Affected Systems

The defect resides in the Linux kernel source tree and affects all builds that compile the arm_scmi firmware driver, regardless of specific version releases. Any system running the legacy ARM SCMI implementation on Linux, including most distributions that ship a recent kernel, is potentially impacted until the driver code is updated to include the unwind fix.

Risk and Exploitability

The EPSS score is reported as less than 1%, indicating a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is most likely local: an attacker with privilege to load a malicious driver or kernel module would need to trigger the failed probe sequence to exhaust the mailbox channel resource. Although there is no remote code execution path, a successful exploitation would compromise system availability by preventing further SCMI communication, which may affect devices relying on the SCMI interface.

Generated by OpenCVE AI on September 19, 2026 at 09:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to the latest stable release from your distribution or vendor that incorporates the mailbox_chan_setup fix for the ARM SCMI driver.
  • Reboot the system after applying the kernel update to clear any residual mailbox channel allocations that could remain from the previous kernel state.
  • If a patched kernel is not yet available, disable or blacklist the arm_scmi driver (e.g., by adding the kernel boot parameter arm_scmi.disable=1) to prevent probe attempts until the update can be applied.

Generated by OpenCVE AI on September 19, 2026 at 09:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-767

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Unwind TX receiver mailbox setup failure mailbox_chan_setup() can request an additional unidirectional TX receiver channel after successfully acquiring the primary channel. If that second request fails, the function returns immediately and leaves the primary channel allocated. Unwind the primary mailbox channel before returning the error so probe deferral or other setup failures do not leave the channel busy for later probe attempts.
Title firmware: arm_scmi: Unwind TX receiver mailbox setup failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:02.997Z

Reserved: 2026-09-17T15:57:05.662Z

Link: CVE-2026-93083

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:02.337

Modified: 2026-09-17T17:18:02.337

Link: CVE-2026-93083

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T17:00:11Z

Weaknesses
  • CWE-767

    Access to Critical Private Variable via Public Method