Impact
The Linux kernel ARM SCMI subsystem contains a use‑after‑free flaw in its notification handling. When an ARM SCMI device is removed or a probe error occurs, the notification instance may still receive callbacks while its underlying TX/RX channels are in the process of being released. During this brief window the driver can dereference freed memory, allowing an attacker with local privileges to corrupt kernel memory or execute arbitrary code in kernel mode.
Affected Systems
This vulnerability affects all Linux kernels that include the arm_scmi module on ARM architectures, regardless of distribution or patch level. It can be triggered when the module is unloaded, a device is removed, or an initialization error happens.
Risk and Exploitability
The CVSS score is not publicly available, but the EPSS score of less than 1% indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local privileged access to trigger teardown of the arm_scmi device, therefore the risk is confined to systems where such privileges exist and the arm_scmi subsystem is loaded. Remote or unauthenticated attacks are unlikely to be effective.
OpenCVE Enrichment
Debian DLA
Debian DSA