-

CVE-2026-93084

firmware: arm_scmi: Drop handle on protocol bind failures

In the Linux kernel, the following vulnerability has been resolved:

firmware: arm_scmi: Drop handle on protocol bind failures

The SCMI bus notifier acquires an SCMI handle when the driver core emits
BUS_NOTIFY_BIND_DRIVER, before invoking the protocol driver probe
callback. The protocol probe path only checks whether sdev->handle is
set.

If device_link_add() fails after the handle has been acquired, the
protocol device can still bind with a valid handle but without the
dependency link to the SCMI parent. A concurrent parent unbind can then
miss the child and tear down the SCMI instance while the child still
holds a handle into it.

If the protocol driver probe later fails, for example with
-EPROBE_DEFER, the driver core emits BUS_NOTIFY_DRIVER_NOT_BOUND rather
than BUS_NOTIFY_UNBOUND_DRIVER. The SCMI notifier only released the
handle on BUS_NOTIFY_UNBOUND_DRIVER, so each failed protocol-device bind
leaked the SCMI instance users refcount and left sdev->handle set after
the failed probe.

Make the link helper report failure and drop the acquired handle if the
link cannot be created. Also handle BUS_NOTIFY_DRIVER_NOT_BOUND in the
same cleanup path used for unbind so failed probes balance the earlier
BUS_NOTIFY_BIND_DRIVER acquisition.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 971fc0665f1361f23251e4d85fac4aed1b683505
Version < 0f860db24ee95e5da4866303a35e55098b9641b3
Status affected
Version 971fc0665f1361f23251e4d85fac4aed1b683505
Version < df273eced7cec550465fd1bb82a5d2c3c7d3c437
Status affected
Version 971fc0665f1361f23251e4d85fac4aed1b683505
Version < a54dc23e8bd2246c28eafffa60b4634f0d1a11cc
Status affected
Version 971fc0665f1361f23251e4d85fac4aed1b683505
Version < 77d2985d1e80e67f32026fc03e975c4c83cc543d
Status affected
Version 971fc0665f1361f23251e4d85fac4aed1b683505
Version < e3a5c30d233ca5d3e799a80da806554c703bda13
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.3
Status affected
Version 0
Version < 6.3
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.065
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/0f860db24ee95e5da4866303a35e55098b9641b3
https://git.kernel.org/stable/c/df273eced7cec550465fd1bb82a5d2c3c7d3c437
https://git.kernel.org/stable/c/a54dc23e8bd2246c28eafffa60b4634f0d1a11cc
https://git.kernel.org/stable/c/77d2985d1e80e67f32026fc03e975c4c83cc543d
https://git.kernel.org/stable/c/e3a5c30d233ca5d3e799a80da806554c703bda13