Executive brief
The Linux kernel's ARM System Control and Management Interface (SCMI) firmware driver has a use-after-free vulnerability during driver removal and error handling. When notifications are being shut down, incoming RX interrupts can still deliver messages and attempt to process freed memory, causing a kernel crash. This vulnerability affects systems using ARM SCMI firmware communication, potentially leading to denial of service.
Technical details
The vulnerability is a use-after-free condition in the ARM SCMI notification subsystem (drivers/firmware/arm_scmi/notify.c and driver.c). During device removal or probe error paths, scmi_notification_exit() clears notification state and releases the notification instance, but transport callbacks can still deliver incoming notifications via RX interrupts until TX/RX channels are freed. An RX interrupt arriving in this window causes scmi_notify() to dereference freed memory. Additionally, the late-init worker queues work on the system workqueue, so destroying the notify_wq does not drain pending work; if the devres group is released while init_work is still running, it can also dereference freed memory. The fix reorders teardown: quiesce the notification core before freeing TX/RX channels using disable_work_sync(), then clean up channels, then release notification resources. This ensures no new notifications are queued and any pending work completes before channel teardown begins.
Affected products
- Linux Linux Kernel All versions with ARM SCMI support; fix applied in upstream and stable branches
Timeline
- 2026-09-17: disclosed: Published on NVD
- 2026-07-14: patched: Fix committed upstream by Sudeep Holla; backported to stable branches