Impact
This flaw occurs in the Linux kernel during the cleanup of SCMI channels. The cleanup routine walks an ID radix tree (IDR) to release resources, but its callback removes entries from the same IDR it is iterating over. Because the iteration has not yet advanced, this removal invalidates the iterator’s state and can corrupt memory. The result is an unsafe kernel state that can lead to a kernel panic or, if an attacker can control the cleanup process, to potential privilege escalation.
Affected Systems
The vulnerability affects the Linux kernel's SCMI subsystem. All installations of the Linux kernel that include the arm_scmi driver and perform channel cleanup are susceptible; specific versions are not enumerated in the advisory.
Risk and Exploitability
The EPSS score is below 1% and the vulnerability is not listed in CISA's KEV catalog, indicating a low probability of exploitation in the wild. However, the lack of a CVSS score in the advisory means the exact severity is undetermined, but the nature of the bug – kernel memory corruption and potential panic – suggests a high impact if successfully triggered. Potential exploitation would likely require local privileged access to induce the cleanup routine, making it a low‑to‑moderate risk for most environments.
OpenCVE Enrichment
Debian DLA
Debian DSA