Executive brief
The Linux kernel's ARM SCMI firmware interface has a race condition in device removal that can lead to a use-after-free error. When two drivers unregister from the same SCMI protocol simultaneously, one thread can free memory while another thread is still accessing it, potentially causing a system crash or unexpected behavior in ARM systems that rely on SCMI for power and performance management.
Technical details
The vulnerability is a use-after-free race condition in the scmi_protocol_device_unrequest() function. The function was dropping a mutex (scmi_requested_devices_mtx) while holding a reference to shared data, then reacquiring it and continuing to use that data. When two concurrent unregister calls occur for the same protocol, one thread can free the per-protocol list head while the other thread is executing a notifier callback outside the mutex. Upon reacquiring the mutex, the second thread dereferences and double-frees the already-freed list head. The fix moves the notifier callback outside the critical section and completes all list/IDR updates and cleanup before releasing the mutex, ensuring the freed memory is not accessed after release. This is a kernel memory management bug affecting the SCMI bus driver; no network attack vector exists.
Affected products
- Linux Linux kernel Multiple versions; patched in commit 2c4097e6c4aed276c5e9ec2ab331ab397ea780bf
Timeline
- 2026-09-17: disclosed
- 2026-07-22: patched: Upstream patch date (commit 2c4097e6c4aed276c5e9ec2ab331ab397ea780bf)