firmware: arm_scmi: Fix SCMI device destroy lifetimes
Summary
| CVE | CVE-2026-93081 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-17 17:18:02 UTC |
| Updated | 2026-09-17 17:18:02 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix SCMI device destroy lifetimes scmi_child_dev_find() drops the reference returned by device_find_child() before returning the scmi_device pointer. A concurrent unregister can then release the device while the destroy path is still using the returned pointer. Make the lookup helper return the device_find_child() reference and keep it until scmi_device_destroy() has finished unregistering the child. Also split device_unregister() in __scmi_device_destroy() so the SCMI bus ID is not made reusable until after device_del() has removed the old scmi_dev.N name from sysfs. This avoids a new SCMI device reusing the same ID while the old device is still registered. The final device release callback is also a possible cleanup path when SCMI children are deleted by driver core recursion rather than __scmi_device_destroy(). Release the SCMI bus ID from a common helper used by destroy, register-failure and final-release paths, and clear scmi_dev->id after freeing it so the final release cannot free the same ID again. |
Risk And Classification
EPSS: 0.001890000 probability, percentile 0.088390000 (date 2026-09-18)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 9ca67840c0ddf3f39407339624cef824a4f27599 c59b3393df1348a12308aaabd5fbc58ed6b21cf5 git | Not specified |
| CNA | Linux | Linux | affected 9ca67840c0ddf3f39407339624cef824a4f27599 6abe8fe36b29ff51d1a42c2f338972883f4751a5 git | Not specified |
| CNA | Linux | Linux | affected 91ff1e9652fb9beb0174267d6bb38243dff211bb git | Not specified |
| CNA | Linux | Linux | affected ff4273d47da81b95ed9396110bcbd1b7b7470fe8 git | Not specified |
| CNA | Linux | Linux | affected 2fbf6c9695ad9f05e7e5c166bf43fac7cb3276b3 git | Not specified |
| CNA | Linux | Linux | affected 969d8beaa2e374387bf9aa5602ef84fc50bb48d8 git | Not specified |
| CNA | Linux | Linux | affected 8a8a3547d5c4960da053df49c75bf623827a25da git | Not specified |
| CNA | Linux | Linux | affected 5.15.182 5.16 semver | Not specified |
| CNA | Linux | Linux | affected 6.1.138 6.2 semver | Not specified |
| CNA | Linux | Linux | affected 6.6.90 6.7 semver | Not specified |
| CNA | Linux | Linux | affected 6.12.28 6.13 semver | Not specified |
| CNA | Linux | Linux | affected 6.14.6 6.15 semver | Not specified |
| CNA | Linux | Linux | affected 6.15 | Not specified |
| CNA | Linux | Linux | unaffected 6.15 semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2.6 7.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.3-rc1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/c59b3393df1348a12308aaabd5fbc58ed6b21cf5 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/6abe8fe36b29ff51d1a42c2f338972883f4751a5 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.