-
CVE-2026-93091
- EPSS 0.17%
- Veröffentlicht 17.09.2026 16:11:07
- Zuletzt bearbeitet 17.09.2026 17:18:03
- Erkennungen
firmware: arm_scmi: Quiesce notifications before teardown
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Quiesce notifications before teardown scmi_notification_exit() clears and releases the notification instance, but transport callbacks can still deliver incoming notifications until the TX/RX channels are freed. During remove, an RX interrupt in that window can enter scmi_notify() while notification state is being torn down and then dereference freed memory. The same ordering exists on the probe error path after notification initialization. The notification late-init worker has a separate lifetime issue: protocol event registration queues ni->init_work on the system workqueue, so destroying ni->notify_wq does not drain that work. If the devres group is released while init_work is still pending or running, the late-init worker can dereference the freed notification instance. Quiesce the notification core before TX/RX channels are torn down, then clean up the channels before releasing the notification core resources. Use disable_work_sync() so future late-init queueing is rejected and any already queued or running late-init work has completed before channel teardown starts.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
1e7cbfaa66d39e78bd24df0c78b55df68176b59e
Version <
6778bcabd2e0c32f73476f0bc6369013692540be
Status
affected
Version
1e7cbfaa66d39e78bd24df0c78b55df68176b59e
Version <
2aac23bc0a79af41104d99823bb250fae92ba144
Status
affected
Version
1e7cbfaa66d39e78bd24df0c78b55df68176b59e
Version <
5e30d3d16d1a9e599be4dcea872874e65e2c277b
Status
affected
Version
1e7cbfaa66d39e78bd24df0c78b55df68176b59e
Version <
8e49055d0d495c9c07575ad8e111d9eaf0efb13f
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.15
Status
affected
Version
0
Version <
5.15
Status
unaffected
Version <=
6.12.*
Version
6.12.110
Status
unaffected
Version <=
6.18.*
Version
6.18.52
Status
unaffected
Version <=
7.2.*
Version
7.2.6
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.065 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/6778bcabd2e0c32f73476f0bc6369013692540be
https://git.kernel.org/stable/c/2aac23bc0a79af41104d99823bb250fae92ba144
https://git.kernel.org/stable/c/5e30d3d16d1a9e599be4dcea872874e65e2c277b
https://git.kernel.org/stable/c/8e49055d0d495c9c07575ad8e111d9eaf0efb13f