{"api_version":"1","generated_at":"2026-09-18T03:22:40+00:00","cve":"CVE-2026-93080","urls":{"html":"https://cve.report/CVE-2026-93080","api":"https://cve.report/api/cve/CVE-2026-93080.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-93080","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-93080"},"summary":{"title":"firmware: arm_scmi: Fix transport device teardown lookup","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_scmi: Fix transport device teardown lookup\n\nSCMI transport devices are deliberately excluded from normal SCMI bus\nmatching so protocol drivers cannot bind to the internal transport\nchildren. However, scmi_device_destroy() uses the same protocol/name\nlookup to find devices that must be unregistered during channel teardown.\n\nSplit the match helper so driver matching still skips transport devices,\nwhile explicit child lookup can find them for teardown. Use a shared\ntransport-device name prefix macro for both matching and name generation.\n\nSince transport-device names are derived from direction and protocol ID,\nreject duplicate protocol channel setup before creating or finding a\ntransport device. This prevents malformed firmware with duplicate\nprotocol child nodes from reusing an existing transport device and then\ndestroying it when the duplicate IDR insertion fails.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-17 17:18:01","updated_at":"2026-09-17 17:18:01"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/c656427440ea627166394d00c4b72147d5d79c60","name":"https://git.kernel.org/stable/c/c656427440ea627166394d00c4b72147d5d79c60","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/a14dd8fe0a95db638c550ed984cfe2a7428c783d","name":"https://git.kernel.org/stable/c/a14dd8fe0a95db638c550ed984cfe2a7428c783d","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/4635953b4c1af477e166073521a77de6279f6929","name":"https://git.kernel.org/stable/c/4635953b4c1af477e166073521a77de6279f6929","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-93080","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93080","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 9593804c44c24545e1b0496786dcb765d7b0e193 c656427440ea627166394d00c4b72147d5d79c60 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 9593804c44c24545e1b0496786dcb765d7b0e193 4635953b4c1af477e166073521a77de6279f6929 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 9593804c44c24545e1b0496786dcb765d7b0e193 a14dd8fe0a95db638c550ed984cfe2a7428c783d git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.16","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.16 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.52 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.6 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/firmware/arm_scmi/bus.c","drivers/firmware/arm_scmi/common.h","drivers/firmware/arm_scmi/driver.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"c656427440ea627166394d00c4b72147d5d79c60","status":"affected","version":"9593804c44c24545e1b0496786dcb765d7b0e193","versionType":"git"},{"lessThan":"4635953b4c1af477e166073521a77de6279f6929","status":"affected","version":"9593804c44c24545e1b0496786dcb765d7b0e193","versionType":"git"},{"lessThan":"a14dd8fe0a95db638c550ed984cfe2a7428c783d","status":"affected","version":"9593804c44c24545e1b0496786dcb765d7b0e193","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/firmware/arm_scmi/bus.c","drivers/firmware/arm_scmi/common.h","drivers/firmware/arm_scmi/driver.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.16"},{"lessThan":"6.16","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.52","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.6","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.52","versionStartIncluding":"6.16","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.6","versionStartIncluding":"6.16","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"6.16","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_scmi: Fix transport device teardown lookup\n\nSCMI transport devices are deliberately excluded from normal SCMI bus\nmatching so protocol drivers cannot bind to the internal transport\nchildren. However, scmi_device_destroy() uses the same protocol/name\nlookup to find devices that must be unregistered during channel teardown.\n\nSplit the match helper so driver matching still skips transport devices,\nwhile explicit child lookup can find them for teardown. Use a shared\ntransport-device name prefix macro for both matching and name generation.\n\nSince transport-device names are derived from direction and protocol ID,\nreject duplicate protocol channel setup before creating or finding a\ntransport device. This prevents malformed firmware with duplicate\nprotocol child nodes from reusing an existing transport device and then\ndestroying it when the duplicate IDR insertion fails."}],"providerMetadata":{"dateUpdated":"2026-09-17T16:11:01.005Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/c656427440ea627166394d00c4b72147d5d79c60"},{"url":"https://git.kernel.org/stable/c/4635953b4c1af477e166073521a77de6279f6929"},{"url":"https://git.kernel.org/stable/c/a14dd8fe0a95db638c550ed984cfe2a7428c783d"}],"title":"firmware: arm_scmi: Fix transport device teardown lookup","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-93080","datePublished":"2026-09-17T16:11:01.005Z","dateReserved":"2026-09-17T15:57:05.662Z","dateUpdated":"2026-09-17T16:11:01.005Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-17 17:18:01","lastModifiedDate":"2026-09-17 17:18:01","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"93080","Ordinal":"1","Title":"firmware: arm_scmi: Fix transport device teardown lookup","CVE":"CVE-2026-93080","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"93080","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_scmi: Fix transport device teardown lookup\n\nSCMI transport devices are deliberately excluded from normal SCMI bus\nmatching so protocol drivers cannot bind to the internal transport\nchildren. However, scmi_device_destroy() uses the same protocol/name\nlookup to find devices that must be unregistered during channel teardown.\n\nSplit the match helper so driver matching still skips transport devices,\nwhile explicit child lookup can find them for teardown. Use a shared\ntransport-device name prefix macro for both matching and name generation.\n\nSince transport-device names are derived from direction and protocol ID,\nreject duplicate protocol channel setup before creating or finding a\ntransport device. This prevents malformed firmware with duplicate\nprotocol child nodes from reusing an existing transport device and then\ndestroying it when the duplicate IDR insertion fails.","Type":"Description","Title":"firmware: arm_scmi: Fix transport device teardown lookup"}]}}}