« Volver al listado

CVE-2026-93081

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

firmware: arm_scmi: Fix SCMI device destroy lifetimes

scmi_child_dev_find() drops the reference returned by device_find_child() before returning the scmi_device pointer. A concurrent unregister can then release the device while the destroy path is still using the returned pointer.

Make the lookup helper return the device_find_child() reference and keep it until scmi_device_destroy() has finished unregistering the child.

Also split device_unregister() in __scmi_device_destroy() so the SCMI bus ID is not made reusable until after device_del() has removed the old scmi_dev.N name from sysfs. This avoids a new SCMI device reusing the same ID while the old device is still registered.

Leer descripción completaMostrar menos

The final device release callback is also a possible cleanup path when SCMI children are deleted by driver core recursion rather than __scmi_device_destroy(). Release the SCMI bus ID from a common helper used by destroy, register-failure and final-release paths, and clear scmi_dev->id after freeing it so the final release cannot free the same ID again.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93081",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "9ca67840c0ddf3f39407339624cef824a4f27599",
              "lessThan": "c59b3393df1348a12308aaabd5fbc58ed6b21cf5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9ca67840c0ddf3f39407339624cef824a4f27599",
              "lessThan": "6abe8fe36b29ff51d1a42c2f338972883f4751a5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "91ff1e9652fb9beb0174267d6bb38243dff211bb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ff4273d47da81b95ed9396110bcbd1b7b7470fe8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2fbf6c9695ad9f05e7e5c166bf43fac7cb3276b3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "969d8beaa2e374387bf9aa5602ef84fc50bb48d8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8a8a3547d5c4960da053df49c75bf623827a25da",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.15.182",
              "lessThan": "5.16",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.1.138",
              "lessThan": "6.2",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.6.90",
              "lessThan": "6.7",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.12.28",
              "lessThan": "6.13",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.14.6",
              "lessThan": "6.15",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "drivers/firmware/arm_scmi/bus.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/firmware/arm_scmi/bus.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:18:02.063",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/6abe8fe36b29ff51d1a42c2f338972883f4751a5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c59b3393df1348a12308aaabd5fbc58ed6b21cf5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_scmi: Fix SCMI device destroy lifetimes\n\nscmi_child_dev_find() drops the reference returned by\ndevice_find_child() before returning the scmi_device pointer. A\nconcurrent unregister can then release the device while the destroy path\nis still using the returned pointer.\n\nMake the lookup helper return the device_find_child() reference and keep\nit until scmi_device_destroy() has finished unregistering the child.\n\nAlso split device_unregister() in __scmi_device_destroy() so the SCMI bus\nID is not made reusable until after device_del() has removed the old\nscmi_dev.N name from sysfs. This avoids a new SCMI device reusing the\nsame ID while the old device is still registered.\n\nThe final device release callback is also a possible cleanup path when\nSCMI children are deleted by driver core recursion rather than\n__scmi_device_destroy(). Release the SCMI bus ID from a common helper\nused by destroy, register-failure and final-release paths, and clear\nscmi_dev->id after freeing it so the final release cannot free the same\nID again."
    }
  ],
  "lastModified": "2026-09-17T17:18:02.063",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}