Description
In the Linux kernel, the following vulnerability has been resolved:

firmware: arm_scmi: Publish channel state before callbacks

Transport setup can enable callbacks before the setup routine returns.
mailbox_chan_setup() registers the mailbox client with
mbox_request_channel(), and the mailbox controller startup path can enable
interrupt delivery before SCMI mailbox channel state has been published.
Similarly, smc_chan_setup() requests the optional A2P completion IRQ before
the SMC transport has made its cinfo pointer visible.

If a pending or spurious callback fires in those windows, the transport RX
callback can dereference a NULL transport cinfo pointer. Publishing only
the transport-private pointer is not sufficient either: an early callback
can enter the SCMI core before scmi_chan_setup() has assigned
cinfo->handle.
The core derives scmi_info from cinfo->handle in the RX path, so a NULL
handle can still fault even when the transport-private cinfo is valid.

Assign cinfo->handle before invoking the transport setup callback. Publish
the mailbox and SMC transport-private channel state before requesting the
mailbox channels or IRQ, and clear the early-published pointers again on
setup failure. Also unwind mailbox setup devres resources on failure so an
optional RX setup error that is ignored by the core does not leave stale
transport state behind.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service – kernel crash due to NULL pointer dereference
Action: Apply patch
AI Analysis

Impact

The vulnerability arises when the ARM SCMI transport registers mailbox or SMC interrupts before the associated channel state is fully published. During this race window a pending or spurious callback can be delivered, causing the receive path to dereference a NULL transport information pointer. The result is an unpredictable kernel failure, typically manifesting as a crash or oops. This denial‑of‑service effect could be exploited by an attacker with kernel or privileged process access to trigger the early callbacks and bring the system down.

Affected Systems

The issue exists in the Linux kernel wherever the ARM SCMI mailbox or SMC transport code is compiled. The known affected products list only the Linux kernel; specific version information is not provided. Consequently any kernel built with the arm_scmi transport that contains the code path described may be vulnerable until the upstream fix is applied.

Risk and Exploitability

The EPSS score is under 1 % indicating a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Because the fault occurs inside kernel space and requires privileged context to trigger the early callback, the attack surface is limited. However, once triggered the impact is catastrophic for uptime. Based on the raw CVSS score (not supplied) and the nature of a NULL pointer dereference, the severity is high, but the exploitation likelihood remains low without an active local vector.

Generated by OpenCVE AI on September 19, 2026 at 07:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update your Linux kernel to a version that includes the arm_scmi patch fixing the channel state publication timing.
  • If an update cannot be applied immediately, disable the ARM SCMI transport or prevent mailbox channel setup until the patch is in place, for example by kernel configuration or removing the module.
  • After applying the fix or disabling the transport, monitor kernel logs for any SCMI‑related oops or null‑pointer dereference messages to confirm mitigation.

Generated by OpenCVE AI on September 19, 2026 at 07:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Publish channel state before callbacks Transport setup can enable callbacks before the setup routine returns. mailbox_chan_setup() registers the mailbox client with mbox_request_channel(), and the mailbox controller startup path can enable interrupt delivery before SCMI mailbox channel state has been published. Similarly, smc_chan_setup() requests the optional A2P completion IRQ before the SMC transport has made its cinfo pointer visible. If a pending or spurious callback fires in those windows, the transport RX callback can dereference a NULL transport cinfo pointer. Publishing only the transport-private pointer is not sufficient either: an early callback can enter the SCMI core before scmi_chan_setup() has assigned cinfo->handle. The core derives scmi_info from cinfo->handle in the RX path, so a NULL handle can still fault even when the transport-private cinfo is valid. Assign cinfo->handle before invoking the transport setup callback. Publish the mailbox and SMC transport-private channel state before requesting the mailbox channels or IRQ, and clear the early-published pointers again on setup failure. Also unwind mailbox setup devres resources on failure so an optional RX setup error that is ignored by the core does not leave stale transport state behind.
Title firmware: arm_scmi: Publish channel state before callbacks
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:08.360Z

Reserved: 2026-09-17T16:02:15.084Z

Link: CVE-2026-93093

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:03.300

Modified: 2026-09-17T17:18:03.300

Link: CVE-2026-93093

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T14:30:07Z

Weaknesses