Junglewise Threat Intelligence

CVE-2026-92506: Linux kernel ARM SCMI use-after-free in device removal

CVE-2026-92506 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's ARM SCMI firmware interface has a race condition in device removal that can lead to a use-after-free error. When two drivers unregister from the same SCMI protocol simultaneously, one thread can free memory while another thread is still accessing it, potentially causing a system crash or unexpected behavior in ARM systems that rely on SCMI for power and performance management.

Technical details

The vulnerability is a use-after-free race condition in the scmi_protocol_device_unrequest() function. The function was dropping a mutex (scmi_requested_devices_mtx) while holding a reference to shared data, then reacquiring it and continuing to use that data. When two concurrent unregister calls occur for the same protocol, one thread can free the per-protocol list head while the other thread is executing a notifier callback outside the mutex. Upon reacquiring the mutex, the second thread dereferences and double-frees the already-freed list head. The fix moves the notifier callback outside the critical section and completes all list/IDR updates and cleanup before releasing the mutex, ensuring the freed memory is not accessed after release. This is a kernel memory management bug affecting the SCMI bus driver; no network attack vector exists.

Affected products

  • Linux Linux kernel Multiple versions; patched in commit 2c4097e6c4aed276c5e9ec2ab331ab397ea780bf

Timeline

  • 2026-09-17: disclosed
  • 2026-07-22: patched: Upstream patch date (commit 2c4097e6c4aed276c5e9ec2ab331ab397ea780bf)

References

Related threats