Impact
The vulnerability occurs in the Linux kernel's ARM System Control and Management Interface (SCMI) firmware driver. When a transport channel is successfully created but an IDR insertion fails, the error path deregisters the device while incorrectly freeing the channel information. Because the driver’s transport cleanup callback is never invoked, existing resources such as IRQs, mailbox channels, and shared memory remain allocated. This resource mismanagement can result in memory leaks and exhaustion of kernel objects, eventually degrading kernel stability or causing a denial of service. The flaw is a classic resource leak identified by CWE‑404 and CWE‑401.
Affected Systems
This defect is present in the Linux kernel source code for all releases that contain the arm_scmi driver referenced in the patch set. The specific affected kernel versions are not enumerated in the advisory, but the commits linked in the references modify the same SCMI transport code. Administrators should verify whether their running kernel contains these. The issue is traced to the Linux:Linux product family on platforms that implement SCMI transport channels.
Risk and Exploitability
The EPSS score is reported as less than 1 %, indicating a very low probability of widespread exploitation today. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation. However, an attacker who can trigger the defective channel creation—such as by malformed firmware, a privileged driver load, or an application that forces SCMI channel reinitialization—could provoke the resource leak, gradually consuming kernel resources and triggering service disruptions. The attack vector is inferred to be local or privileged, as the error occurs during kernel device initialization, but it could be extended through firmware interfaces that an authenticated user controls. Given the lack of immediate exploitation evidence, the overall risk remains moderate, but patching is recommended to prevent potential denial of service.
OpenCVE Enrichment
Debian DLA
Debian DSA