Description
In the Linux kernel, the following vulnerability has been resolved:

firmware: arm_scmi: Unregister device notifier before IDR teardown

The requested-devices notifier looks up protocol fwnodes from the
active_protocols IDR. During remove, unregister the notifier before
releasing and destroying active_protocols so no notifier callback can race
with the IDR teardown.

Keep the bus notifier registered until after the protocol state is torn
down, matching the existing remove ordering for SCMI bus users.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via kernel crash
Action: Update Kernel
AI Analysis

Impact

The Linux kernel contains a race condition in the SCMI bus driver where a device notifier is unregistered after the internal IDR that holds protocol entries is torn down. If the notifier callback is invoked during this teardown sequence, it may access freed resources, leading to a kernel panic and loss of availability. The vulnerability does not provide direct data disclosure or privilege escalation but can render a system unusable.

Affected Systems

All Linux kernel releases that include the SCMI bus driver and load the arm_scmi module are affected. The patch is present in a kernel commit referenced in the advisory but no specific release numbers are enumerated. Any machine running a kernel that contains the SCMI interface without this fix is potentially vulnerable.

Risk and Exploitability

The EPSS score is less than 1% and the vulnerability is not listed in CISA KEV, indicating a low likelihood of active exploitation. The issue requires a race condition between notifier removal and IDR teardown, which is not trivially triggerable for a remote attacker. Based on the description, it is inferred that the attacker would need local or hardware‑level access to the SCMI bus to manipulate the teardown sequence. If the race is triggered, a kernel crash will occur, resulting in denial of service. The overall risk is considered low to moderate given the exploitation difficulty and the lack of a public exploit.

Generated by OpenCVE AI on September 19, 2026 at 09:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the SCMI driver patch for this race condition.
  • If an upgrade cannot be performed immediately, disable the arm_scmi driver or unbind the SCMI bus so that notifier callbacks cannot be invoked during protocol teardown.
  • Reboot the machine after applying the patch or disabling the driver to ensure the change takes effect.

Generated by OpenCVE AI on September 19, 2026 at 09:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Unregister device notifier before IDR teardown The requested-devices notifier looks up protocol fwnodes from the active_protocols IDR. During remove, unregister the notifier before releasing and destroying active_protocols so no notifier callback can race with the IDR teardown. Keep the bus notifier registered until after the protocol state is torn down, matching the existing remove ordering for SCMI bus users.
Title firmware: arm_scmi: Unregister device notifier before IDR teardown
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:07.715Z

Reserved: 2026-09-17T16:02:15.084Z

Link: CVE-2026-93092

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:03.177

Modified: 2026-09-17T17:18:03.177

Link: CVE-2026-93092

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T08:45:17Z

Weaknesses