Impact
When the arm_scmi driver’s channel setup routine fails after provisioning some channels, the kernel fails to release the channels, transport devices, and identifier reservation tables that were allocated beforehand. This omission creates a resource leak that can accumulate over repeated failures, eventually exhausting kernel memory or leaving dangling references that may trigger instability or a denial‑of‑service scenario when the arm_scmi instance is freed.
Affected Systems
All Linux kernel builds that include the arm_scmi driver, typically on ARM‑based systems that use System Control and Management Interface channels. Any deployment that loads the arm_scmi driver at boot or runtime is affected.
Risk and Exploitability
The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation. Because the flaw manifests during driver initialization, the attack vector is likely local privileged; an attacker would need to trigger the failure path during arm_scmi loading. No evidence suggests a viable remote exploitation path.
OpenCVE Enrichment
Debian DLA
Debian DSA