remoteproc: scp: Fix device reference leak on failed lookup
Summary
| CVE | CVE-2026-89512 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-11 20:19:33 UTC |
| Updated | 2026-09-11 20:19:33 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: remoteproc: scp: Fix device reference leak on failed lookup Make sure to drop the reference taken to the SCP device when attempting to look up its driver data before the driver has been bound. Note that holding a reference to a device does not prevent its driver data from going away. |
Risk And Classification
EPSS: 0.002000000 probability, percentile 0.099430000 (date 2026-09-13)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 63c13d61eafe4606f1c16c54da40c4eee78e9edf f794c930d8238e370fd61fcb12cc301ae098231b git | Not specified |
| CNA | Linux | Linux | affected 63c13d61eafe4606f1c16c54da40c4eee78e9edf c7e32814a6bf20f792d05f0bc9f94f0606311bc6 git | Not specified |
| CNA | Linux | Linux | affected 63c13d61eafe4606f1c16c54da40c4eee78e9edf 440bcb0948a12c9104b6dcca99a2cfb0db49b22a git | Not specified |
| CNA | Linux | Linux | affected 63c13d61eafe4606f1c16c54da40c4eee78e9edf 22f9efb3ae07f966a1901d929d16df1388cce65c git | Not specified |
| CNA | Linux | Linux | affected 5.6 | Not specified |
| CNA | Linux | Linux | unaffected 5.6 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.109 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.50 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2.4 7.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.3-rc1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/440bcb0948a12c9104b6dcca99a2cfb0db49b22a | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/f794c930d8238e370fd61fcb12cc301ae098231b | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/c7e32814a6bf20f792d05f0bc9f94f0606311bc6 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/22f9efb3ae07f966a1901d929d16df1388cce65c | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.