PT-2026-94882 · Linux · Linux Kernel
CVE-2026-93084
·
Published
2026-09-17
·
Updated
2026-09-28
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the
arm scmi firmware component where the SCMI bus notifier fails to release an SCMI handle during protocol bind failures. When the driver core emits BUS NOTIFY BIND DRIVER, a handle is acquired before the protocol driver probe callback. If device link add() fails, a protocol device may bind with a valid handle but without a dependency link to the SCMI parent, potentially leading to a use-after-free scenario if a concurrent parent unbind occurs. Additionally, if the protocol driver probe fails with -EPROBE DEFER, the driver core emits BUS NOTIFY DRIVER NOT BOUND. Because the SCMI notifier only released handles on BUS NOTIFY UNBOUND DRIVER, this results in a leak of the SCMI instance users refcount and leaves sdev->handle set after a failed probe.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel