Junglewise Threat Intelligence

CVE-2026-93090: Linux kernel ARM SCMI firmware channel cleanup resource leak

CVE-2026-93090 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's ARM SCMI firmware subsystem failed to properly clean up communication channels when setup encountered errors, leaving transport devices and internal data structures in an inconsistent state. This could cause memory leaks or system instability if channel initialization fails during device probe.

Technical details

The vulnerability is a resource leak in the ARM SCMI (Scalable Computing Management Interface) firmware driver's channel setup function. When scmi_channels_setup() fails after already registering channels in the TX/RX IDRs (ID registries), the error path was incorrectly jumping to a cleanup label that skipped transport channel and device cleanup, leaving allocated resources orphaned. The fix routes channel setup failures through the correct cleanup label (clear_txrx_setup) instead of an earlier label (clear_ida), ensuring scmi_cleanup_txrx_channels() is called to release transport channels and devices before freeing the SCMI instance ID.

Affected products

  • Linux Linux kernel all versions affected by commit 05a2801d8b90 onwards

Timeline

  • 2026-09-17: disclosed
  • 2026-07-14: patched

References

Related threats