Impact
The Linux kernel contains a race condition in the SCMI bus driver where a device notifier is unregistered after the internal IDR that holds protocol entries is torn down. If the notifier callback is invoked during this teardown sequence, it may access freed resources, leading to a kernel panic and loss of availability. The vulnerability does not provide direct data disclosure or privilege escalation but can render a system unusable.
Affected Systems
All Linux kernel releases that include the SCMI bus driver and load the arm_scmi module are affected. The patch is present in a kernel commit referenced in the advisory but no specific release numbers are enumerated. Any machine running a kernel that contains the SCMI interface without this fix is potentially vulnerable.
Risk and Exploitability
The EPSS score is less than 1% and the vulnerability is not listed in CISA KEV, indicating a low likelihood of active exploitation. The issue requires a race condition between notifier removal and IDR teardown, which is not trivially triggerable for a remote attacker. Based on the description, it is inferred that the attacker would need local or hardware‑level access to the SCMI bus to manipulate the teardown sequence. If the race is triggered, a kernel crash will occur, resulting in denial of service. The overall risk is considered low to moderate given the exploitation difficulty and the lack of a public exploit.
OpenCVE Enrichment
Debian DLA
Debian DSA