-

CVE-2026-93081

firmware: arm_scmi: Fix SCMI device destroy lifetimes

In the Linux kernel, the following vulnerability has been resolved:

firmware: arm_scmi: Fix SCMI device destroy lifetimes

scmi_child_dev_find() drops the reference returned by
device_find_child() before returning the scmi_device pointer. A
concurrent unregister can then release the device while the destroy path
is still using the returned pointer.

Make the lookup helper return the device_find_child() reference and keep
it until scmi_device_destroy() has finished unregistering the child.

Also split device_unregister() in __scmi_device_destroy() so the SCMI bus
ID is not made reusable until after device_del() has removed the old
scmi_dev.N name from sysfs. This avoids a new SCMI device reusing the
same ID while the old device is still registered.

The final device release callback is also a possible cleanup path when
SCMI children are deleted by driver core recursion rather than
__scmi_device_destroy(). Release the SCMI bus ID from a common helper
used by destroy, register-failure and final-release paths, and clear
scmi_dev->id after freeing it so the final release cannot free the same
ID again.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 9ca67840c0ddf3f39407339624cef824a4f27599
Version < c59b3393df1348a12308aaabd5fbc58ed6b21cf5
Status affected
Version 9ca67840c0ddf3f39407339624cef824a4f27599
Version < 6abe8fe36b29ff51d1a42c2f338972883f4751a5
Status affected
Version 91ff1e9652fb9beb0174267d6bb38243dff211bb
Status affected
Version ff4273d47da81b95ed9396110bcbd1b7b7470fe8
Status affected
Version 2fbf6c9695ad9f05e7e5c166bf43fac7cb3276b3
Status affected
Version 969d8beaa2e374387bf9aa5602ef84fc50bb48d8
Status affected
Version 8a8a3547d5c4960da053df49c75bf623827a25da
Status affected
Version 5.15.182
Version < 5.16
Status affected
Version 6.1.138
Version < 6.2
Status affected
Version 6.6.90
Version < 6.7
Status affected
Version 6.12.28
Version < 6.13
Status affected
Version 6.14.6
Version < 6.15
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.15
Status affected
Version 0
Version < 6.15
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.088
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/c59b3393df1348a12308aaabd5fbc58ed6b21cf5
https://git.kernel.org/stable/c/6abe8fe36b29ff51d1a42c2f338972883f4751a5