Description
In the Linux kernel, the following vulnerability has been resolved:

firmware: arm_scmi: Free transport channel on IDR failure

If transport channel setup succeeds but the following IDR insertion fails,
the error path destroys the transport device and frees the channel info
without invoking the transport cleanup callback.

Call chan_free() before destroying the device so transport specific
resources such as IRQs, mailbox channels and mapped shared memory are
released consistently with the normal teardown path.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Resource Leak leading to Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability occurs in the Linux kernel's ARM System Control and Management Interface (SCMI) firmware driver. When a transport channel is successfully created but an IDR insertion fails, the error path deregisters the device while incorrectly freeing the channel information. Because the driver’s transport cleanup callback is never invoked, existing resources such as IRQs, mailbox channels, and shared memory remain allocated. This resource mismanagement can result in memory leaks and exhaustion of kernel objects, eventually degrading kernel stability or causing a denial of service. The flaw is a classic resource leak identified by CWE‑404 and CWE‑401.

Affected Systems

This defect is present in the Linux kernel source code for all releases that contain the arm_scmi driver referenced in the patch set. The specific affected kernel versions are not enumerated in the advisory, but the commits linked in the references modify the same SCMI transport code. Administrators should verify whether their running kernel contains these. The issue is traced to the Linux:Linux product family on platforms that implement SCMI transport channels.

Risk and Exploitability

The EPSS score is reported as less than 1 %, indicating a very low probability of widespread exploitation today. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation. However, an attacker who can trigger the defective channel creation—such as by malformed firmware, a privileged driver load, or an application that forces SCMI channel reinitialization—could provoke the resource leak, gradually consuming kernel resources and triggering service disruptions. The attack vector is inferred to be local or privileged, as the error occurs during kernel device initialization, but it could be extended through firmware interfaces that an authenticated user controls. Given the lack of immediate exploitation evidence, the overall risk remains moderate, but patching is recommended to prevent potential denial of service.

Generated by OpenCVE AI on September 19, 2026 at 07:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that contains the SCMI transport cleanup patch.
  • Temporarily disable the SCMI transport layer by removing the corresponding kernel module or recompiling the kernel without the arm_scmi driver until the patch is available.
  • After patching or disabling, reboot the system and monitor kernel logs for any residual resource exhaustion warnings.
  • Verify that firmware updates for ARM devices do not reintroduce the faulty IDR insertion logic.

Generated by OpenCVE AI on September 19, 2026 at 07:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401
CWE-404

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Free transport channel on IDR failure If transport channel setup succeeds but the following IDR insertion fails, the error path destroys the transport device and frees the channel info without invoking the transport cleanup callback. Call chan_free() before destroying the device so transport specific resources such as IRQs, mailbox channels and mapped shared memory are released consistently with the normal teardown path.
Title firmware: arm_scmi: Free transport channel on IDR failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:05.713Z

Reserved: 2026-09-17T16:02:15.083Z

Link: CVE-2026-93089

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:02.840

Modified: 2026-09-17T17:18:02.840

Link: CVE-2026-93089

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T16:45:16Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime

  • CWE-404

    Improper Resource Shutdown or Release