Junglewise Threat Intelligence

CVE-2026-93081: Linux kernel ARM SCMI firmware race condition in device destroy

CVE-2026-93081 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's ARM SCMI firmware driver contains a reference-counting race condition in device cleanup. When a device is being destroyed, a concurrent unregister operation can prematurely release the device while the destroy path is still using it, potentially causing a use-after-free condition. This could allow an attacker with local access to trigger a kernel crash or execute arbitrary code.

Technical details

The vulnerability is a use-after-free race condition in the ARM SCMI (System Control and Management Interface) firmware driver's device lifecycle management. The root cause is in the scmi_child_dev_find() helper function, which drops the reference returned by device_find_child() before returning the scmi_device pointer to the caller. This allows a concurrent device unregister operation to release the device while the destroy path is still holding and using the pointer. Additionally, the device ID allocation was being released before device_del() completed, allowing ID reuse while the old device was still registered in sysfs. The fix involves returning and holding the device_find_child() reference until destroy completes, splitting device_unregister() to delay ID release until after device_del(), and ensuring the bus ID is released from a common helper used by all cleanup paths. The vulnerability is a local issue requiring no network access or authentication.

Affected products

  • Linux Linux kernel Linux 5.10 and later (up to and including 6.13)

Timeline

  • 2026-09-17: disclosed: CVE published
  • 2026-07-14: patched: Fix committed upstream (commit 6abe8fe36b29ff51d1a42c2f338972883f4751a5)
  • 2026-09-14: other: Fix included in stable Linux releases (backport commit c59b3393df1348a12308aaabd5fbc58ed6b21cf5)

References

Related threats