Executive brief
The Linux kernel's ARM System Control and Management Interface (SCMI) firmware driver contains a resource cleanup bug in transport channel initialization. When a transport channel is successfully set up but the subsequent IDR (ID Radix tree) registration fails, system resources such as IRQs, mailbox channels, and shared memory mappings are not properly released, leading to resource exhaustion and potential system instability.
Technical details
The vulnerability is a resource leak in drivers/firmware/arm_scmi/driver.c in the SCMI transport channel initialization code. When IDR allocation fails after successful transport channel setup, the error handler destroys the device and frees channel info without invoking the transport-specific cleanup callback (chan_free). This leaves transport resources like IRQs, mailbox channels, and mapped shared memory in an allocated state. The fix adds a call to chan_free() before device destruction to ensure consistent resource cleanup between error and normal teardown paths. The fix is a single-line addition to the error path, available in Linux kernel commits d72e7e5f and ae7980c9.
Affected products
- Linux Linux kernel Kernel versions from introduction of commit 05a2801d8b90 through multiple stable series
Timeline
- 2026-09-17: disclosed: Published in NVD
- 2026-07-14: patched: Upstream patch committed to Linux kernel