Impact
In the Linux kernel, the arm_scmi firmware driver accepts protocol identifiers from device tree entries that exceed the maximum value defined by MSG_PROTOCOL_ID_MASK. These out‑of‑range IDs are only logged as an error and are still used within helper code that treats the value as an 8‑bit protocol ID. When an attacker supplies a malformed 32‑bit DT reg value, the value is truncated or interpreted as an entirely different protocol ID. This allows the creation of protocol identity instances that alias other protocols or establish SCMI channels under a forged identity, potentially granting unauthorized access or privilege escalation.
Affected Systems
The affected product is the Linux kernel’s SCMI (System Control and Management Interface) implementation, specifically the arm_scmi subsystem that parses DT protocol nodes. No specific kernel version ranges are provided in the CNA data, so any kernel build that includes the arm_scmi driver and processes device tree entries may be vulnerable.
Risk and Exploitability
The CVE reports no CVSS score; however, the EPSS score is reported as less than 1 % and the vulnerability is not listed in CISA’s KEV catalog, indicating a low likelihood of widespread exploitation. Nevertheless, the flaw can be exploited by an attacker who can influence the device tree—either locally or via a compromised firmware update—to inject out‑of‑range protocol IDs, which could lead to the improper establishment of SCMI channels or unauthorized control over platform subsystems. The attack vector is therefore likely local, although it could be made remote if firmware can be altered from an external source.
OpenCVE Enrichment
Debian DLA
Debian DSA