CVE-2026-92490
In the Linux kernel, the following vulnerability has been resolved:
firmware: arm_scmi: Unrequest devices if driver registration fails
scmi_driver_register() requests protocol devices before registering the driver. If driver_register() fails, those requests remain in the global IDR and retain pointers to the module's ID table. Once the failed module load releases that storage, later request matching or SCMI device creation can dereference the stale pointers.
Unrequest the complete protocol table before returning the registration failure. At this point table registration succeeded, so every entry is owned by the current registration attempt.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/06e65e07a1bcb39a1ebc8bb89a981f8e07900497
- https://git.kernel.org/stable/c/4520d4a1db37198756ad23568e36cdf091b6ffff
- https://git.kernel.org/stable/c/524e57035af2d32498af9dd8fa6fdc92fcc8f80a
- https://git.kernel.org/stable/c/9f7cd6a62aa754ed6b48cbd5d50de40add1bcc86
- https://git.kernel.org/stable/c/a76b20b1f03099204db29b90e1024fe1c2b2cdd7
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-92490",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "d3cd7c525fd2ecce3a6c963f314969a54783d211",
"lessThan": "524e57035af2d32498af9dd8fa6fdc92fcc8f80a",
"versionType": "git"
},
{
"status": "affected",
"version": "d3cd7c525fd2ecce3a6c963f314969a54783d211",
"lessThan": "06e65e07a1bcb39a1ebc8bb89a981f8e07900497",
"versionType": "git"
},
{
"status": "affected",
"version": "d3cd7c525fd2ecce3a6c963f314969a54783d211",
"lessThan": "a76b20b1f03099204db29b90e1024fe1c2b2cdd7",
"versionType": "git"
},
{
"status": "affected",
"version": "d3cd7c525fd2ecce3a6c963f314969a54783d211",
"lessThan": "4520d4a1db37198756ad23568e36cdf091b6ffff",
"versionType": "git"
},
{
"status": "affected",
"version": "d3cd7c525fd2ecce3a6c963f314969a54783d211",
"lessThan": "9f7cd6a62aa754ed6b48cbd5d50de40add1bcc86",
"versionType": "git"
}
],
"programFiles": [
"drivers/firmware/arm_scmi/bus.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.3"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.3",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.52",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/firmware/arm_scmi/bus.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:17:51.123",
"references": [
{
"url": "https://git.kernel.org/stable/c/06e65e07a1bcb39a1ebc8bb89a981f8e07900497",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/4520d4a1db37198756ad23568e36cdf091b6ffff",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/524e57035af2d32498af9dd8fa6fdc92fcc8f80a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9f7cd6a62aa754ed6b48cbd5d50de40add1bcc86",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a76b20b1f03099204db29b90e1024fe1c2b2cdd7",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_scmi: Unrequest devices if driver registration fails\n\nscmi_driver_register() requests protocol devices before registering the\ndriver. If driver_register() fails, those requests remain in the global\nIDR and retain pointers to the module's ID table. Once the failed module\nload releases that storage, later request matching or SCMI device creation\ncan dereference the stale pointers.\n\nUnrequest the complete protocol table before returning the registration\nfailure. At this point table registration succeeded, so every entry is\nowned by the current registration attempt."
}
],
"lastModified": "2026-09-17T17:17:51.123",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}