Impact
The flaw arises when the SCMI bus notifier acquires an SCMI handle during driver binding without ensuring that the subsequent link creation succeeds. If the link fails, the handle remains, causing a reference-count leak in the SCMI instance. When the parent device later unbinds, the held handle may reference a freed instance, potentially leading to kernel crashes or undefined behavior. This improper cleanup represents a resource-management error.
Affected Systems
All Linux kernel builds that include the ARM SCMI protocol driver, as indicated by the vendor listing "Linux:Linux". No specific version range is supplied, implying that any kernel lacking the upstream fix could be affected.
Risk and Exploitability
The EPSS score of less than 1% indicates a very low likelihood that this flaw will be exploited in the wild. Because the vulnerability requires a failure in the SCMI protocol driver bind process, it is typically triggered by a local privileged process or during kernel boot, making remote exploitation unlikely. The flaw is not present in CISA’s KEV catalog, underscoring its low threat level. Nevertheless, in environments where SCMI is critical for inter‑component communication, improper cleanup could compromise system stability or cause crashes.
OpenCVE Enrichment
Debian DLA
Debian DSA