Description
In the Linux kernel, the following vulnerability has been resolved:

firmware: arm_scmi: Avoid IDR updates while cleaning channels

scmi_cleanup_channels() walks the TX/RX channel IDRs with
idr_for_each() to free transport resources and destroy the dedicated
transport devices before calling idr_destroy().

The destroy callback removed each entry from the same IDR being walked.
That is not needed for this cleanup path, and it is unsafe because
idr_for_each() has not advanced its radix-tree iterator while the
callback is running. Removing the current entry from the callback can
invalidate the iterator state. The callback also cannot be protected by
rcu_read_lock(), because scmi_device_destroy() may sleep.

Leave IDR teardown to the following idr_destroy() call and keep the
callback limited to device destruction.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Crash leading to Denial of Service
Action: Patch Immediately
AI Analysis

Impact

This flaw occurs in the Linux kernel during the cleanup of SCMI channels. The cleanup routine walks an ID radix tree (IDR) to release resources, but its callback removes entries from the same IDR it is iterating over. Because the iteration has not yet advanced, this removal invalidates the iterator’s state and can corrupt memory. The result is an unsafe kernel state that can lead to a kernel panic or, if an attacker can control the cleanup process, to potential privilege escalation.

Affected Systems

The vulnerability affects the Linux kernel's SCMI subsystem. All installations of the Linux kernel that include the arm_scmi driver and perform channel cleanup are susceptible; specific versions are not enumerated in the advisory.

Risk and Exploitability

The EPSS score is below 1% and the vulnerability is not listed in CISA's KEV catalog, indicating a low probability of exploitation in the wild. However, the lack of a CVSS score in the advisory means the exact severity is undetermined, but the nature of the bug – kernel memory corruption and potential panic – suggests a high impact if successfully triggered. Potential exploitation would likely require local privileged access to induce the cleanup routine, making it a low‑to‑moderate risk for most environments.

Generated by OpenCVE AI on September 19, 2026 at 07:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that contains the fix for the SCMI cleanup routine
  • Reboot the system after applying the kernel update to ensure the new code is active
  • If updating the kernel is not immediately possible, disable SCMI support or prevent SCMI channel cleanup through configuration or system controls

Generated by OpenCVE AI on September 19, 2026 at 07:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Avoid IDR updates while cleaning channels scmi_cleanup_channels() walks the TX/RX channel IDRs with idr_for_each() to free transport resources and destroy the dedicated transport devices before calling idr_destroy(). The destroy callback removed each entry from the same IDR being walked. That is not needed for this cleanup path, and it is unsafe because idr_for_each() has not advanced its radix-tree iterator while the callback is running. Removing the current entry from the callback can invalidate the iterator state. The callback also cannot be protected by rcu_read_lock(), because scmi_device_destroy() may sleep. Leave IDR teardown to the following idr_destroy() call and keep the callback limited to device destruction.
Title firmware: arm_scmi: Avoid IDR updates while cleaning channels
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:05.025Z

Reserved: 2026-09-17T15:57:05.662Z

Link: CVE-2026-93086

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:02.713

Modified: 2026-09-17T17:18:02.713

Link: CVE-2026-93086

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:45:11Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')