Description
In the Linux kernel, the following vulnerability has been resolved:

firmware: arm_scmi: Quiesce notifications before teardown

scmi_notification_exit() clears and releases the notification instance,
but transport callbacks can still deliver incoming notifications until
the TX/RX channels are freed. During remove, an RX interrupt in that
window can enter scmi_notify() while notification state is being torn
down and then dereference freed memory. The same ordering exists on the
probe error path after notification initialization.

The notification late-init worker has a separate lifetime issue: protocol
event registration queues ni->init_work on the system workqueue, so
destroying ni->notify_wq does not drain that work. If the devres group is
released while init_work is still pending or running, the late-init worker
can dereference the freed notification instance.

Quiesce the notification core before TX/RX channels are torn down, then
clean up the channels before releasing the notification core resources.
Use disable_work_sync() so future late-init queueing is rejected and any
already queued or running late-init work has completed before channel
teardown starts.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Arbitrary Code Execution
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel ARM SCMI subsystem contains a use‑after‑free flaw in its notification handling. When an ARM SCMI device is removed or a probe error occurs, the notification instance may still receive callbacks while its underlying TX/RX channels are in the process of being released. During this brief window the driver can dereference freed memory, allowing an attacker with local privileges to corrupt kernel memory or execute arbitrary code in kernel mode.

Affected Systems

This vulnerability affects all Linux kernels that include the arm_scmi module on ARM architectures, regardless of distribution or patch level. It can be triggered when the module is unloaded, a device is removed, or an initialization error happens.

Risk and Exploitability

The CVSS score is not publicly available, but the EPSS score of less than 1% indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local privileged access to trigger teardown of the arm_scmi device, therefore the risk is confined to systems where such privileges exist and the arm_scmi subsystem is loaded. Remote or unauthenticated attacks are unlikely to be effective.

Generated by OpenCVE AI on September 19, 2026 at 09:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest GitHub backport or kernel release that includes the arm_scmi quiesce notification patch
  • If a kernel upgrade cannot be performed immediately, disable or unload the arm_scmi module to prevent the vulnerable code from executing
  • Reboot the system after disabling the module to allow any queued work to finish and memory to be freed safely

Generated by OpenCVE AI on September 19, 2026 at 09:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Quiesce notifications before teardown scmi_notification_exit() clears and releases the notification instance, but transport callbacks can still deliver incoming notifications until the TX/RX channels are freed. During remove, an RX interrupt in that window can enter scmi_notify() while notification state is being torn down and then dereference freed memory. The same ordering exists on the probe error path after notification initialization. The notification late-init worker has a separate lifetime issue: protocol event registration queues ni->init_work on the system workqueue, so destroying ni->notify_wq does not drain that work. If the devres group is released while init_work is still pending or running, the late-init worker can dereference the freed notification instance. Quiesce the notification core before TX/RX channels are torn down, then clean up the channels before releasing the notification core resources. Use disable_work_sync() so future late-init queueing is rejected and any already queued or running late-init work has completed before channel teardown starts.
Title firmware: arm_scmi: Quiesce notifications before teardown
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:07.055Z

Reserved: 2026-09-17T16:02:15.084Z

Link: CVE-2026-93091

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:03.063

Modified: 2026-09-17T17:18:03.063

Link: CVE-2026-93091

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T16:30:17Z

Weaknesses