Junglewise Threat Intelligence

CVE-2026-93091: Linux kernel ARM SCMI firmware use-after-free in notification teardown

CVE-2026-93091 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's ARM System Control and Management Interface (SCMI) firmware driver has a use-after-free vulnerability during driver removal and error handling. When notifications are being shut down, incoming RX interrupts can still deliver messages and attempt to process freed memory, causing a kernel crash. This vulnerability affects systems using ARM SCMI firmware communication, potentially leading to denial of service.

Technical details

The vulnerability is a use-after-free condition in the ARM SCMI notification subsystem (drivers/firmware/arm_scmi/notify.c and driver.c). During device removal or probe error paths, scmi_notification_exit() clears notification state and releases the notification instance, but transport callbacks can still deliver incoming notifications via RX interrupts until TX/RX channels are freed. An RX interrupt arriving in this window causes scmi_notify() to dereference freed memory. Additionally, the late-init worker queues work on the system workqueue, so destroying the notify_wq does not drain pending work; if the devres group is released while init_work is still running, it can also dereference freed memory. The fix reorders teardown: quiesce the notification core before freeing TX/RX channels using disable_work_sync(), then clean up channels, then release notification resources. This ensures no new notifications are queued and any pending work completes before channel teardown begins.

Affected products

  • Linux Linux Kernel All versions with ARM SCMI support; fix applied in upstream and stable branches

Timeline

  • 2026-09-17: disclosed: Published on NVD
  • 2026-07-14: patched: Fix committed upstream by Sudeep Holla; backported to stable branches

References

Related threats