firmware: arm_scmi: Free transport channel on IDR failure

Summary

CVECVE-2026-93089
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-09-17 17:18:02 UTC
Updated2026-09-17 17:18:02 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Free transport channel on IDR failure If transport channel setup succeeds but the following IDR insertion fails, the error path destroys the transport device and frees the channel info without invoking the transport cleanup callback. Call chan_free() before destroying the device so transport specific resources such as IRQs, mailbox channels and mapped shared memory are released consistently with the normal teardown path.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 05a2801d8b90c1b5159618d4bd3a3c65d60f3ff1 ae7980c9af698d0a7e6790d49249abc71f0fc304 git Not specified
CNA Linux Linux affected 05a2801d8b90c1b5159618d4bd3a3c65d60f3ff1 de0a4c103740cf54cf77370d47e03c9aa51aa5ee git Not specified
CNA Linux Linux affected 05a2801d8b90c1b5159618d4bd3a3c65d60f3ff1 d7c60c0fe2bd452b56fe07947842d64da61b7290 git Not specified
CNA Linux Linux affected 05a2801d8b90c1b5159618d4bd3a3c65d60f3ff1 fbaebd380caa4e1cec9306ca00231da6518a123f git Not specified
CNA Linux Linux affected 05a2801d8b90c1b5159618d4bd3a3c65d60f3ff1 d72e7e5f24687c0490aabf317653caffe0447aeb git Not specified
CNA Linux Linux affected 6.3 Not specified
CNA Linux Linux unaffected 6.3 semver Not specified
CNA Linux Linux unaffected 6.6.157 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.110 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.52 6.18.* semver Not specified
CNA Linux Linux unaffected 7.2.6 7.2.* semver Not specified
CNA Linux Linux unaffected 7.3-rc1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/fbaebd380caa4e1cec9306ca00231da6518a123f 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/ae7980c9af698d0a7e6790d49249abc71f0fc304 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/d7c60c0fe2bd452b56fe07947842d64da61b7290 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/d72e7e5f24687c0490aabf317653caffe0447aeb 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/de0a4c103740cf54cf77370d47e03c9aa51aa5ee 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report