CVE-2026-93089
In the Linux kernel, the following vulnerability has been resolved:
firmware: arm_scmi: Free transport channel on IDR failure
If transport channel setup succeeds but the following IDR insertion fails, the error path destroys the transport device and frees the channel info without invoking the transport cleanup callback.
Call chan_free() before destroying the device so transport specific resources such as IRQs, mailbox channels and mapped shared memory are released consistently with the normal teardown path.
CVSS
NVD hasn't assigned a CVSS score to this CVE (common since the April 2026 policy change).
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.21%
- Percentile among all scored CVEs: 10
- Score date: 10/3/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
References
- https://git.kernel.org/stable/c/ae7980c9af698d0a7e6790d49249abc71f0fc304
- https://git.kernel.org/stable/c/d72e7e5f24687c0490aabf317653caffe0447aeb
- https://git.kernel.org/stable/c/d7c60c0fe2bd452b56fe07947842d64da61b7290
- https://git.kernel.org/stable/c/de0a4c103740cf54cf77370d47e03c9aa51aa5ee
- https://git.kernel.org/stable/c/fbaebd380caa4e1cec9306ca00231da6518a123f
Raw JSON (NVD)
Show
{
"id": "CVE-2026-93089",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "05a2801d8b90c1b5159618d4bd3a3c65d60f3ff1",
"lessThan": "ae7980c9af698d0a7e6790d49249abc71f0fc304",
"versionType": "git"
},
{
"status": "affected",
"version": "05a2801d8b90c1b5159618d4bd3a3c65d60f3ff1",
"lessThan": "de0a4c103740cf54cf77370d47e03c9aa51aa5ee",
"versionType": "git"
},
{
"status": "affected",
"version": "05a2801d8b90c1b5159618d4bd3a3c65d60f3ff1",
"lessThan": "d7c60c0fe2bd452b56fe07947842d64da61b7290",
"versionType": "git"
},
{
"status": "affected",
"version": "05a2801d8b90c1b5159618d4bd3a3c65d60f3ff1",
"lessThan": "fbaebd380caa4e1cec9306ca00231da6518a123f",
"versionType": "git"
},
{
"status": "affected",
"version": "05a2801d8b90c1b5159618d4bd3a3c65d60f3ff1",
"lessThan": "d72e7e5f24687c0490aabf317653caffe0447aeb",
"versionType": "git"
}
],
"programFiles": [
"drivers/firmware/arm_scmi/driver.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.3"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.3",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.52",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/firmware/arm_scmi/driver.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:18:02.840",
"references": [
{
"url": "https://git.kernel.org/stable/c/ae7980c9af698d0a7e6790d49249abc71f0fc304",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d72e7e5f24687c0490aabf317653caffe0447aeb",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d7c60c0fe2bd452b56fe07947842d64da61b7290",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/de0a4c103740cf54cf77370d47e03c9aa51aa5ee",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/fbaebd380caa4e1cec9306ca00231da6518a123f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_scmi: Free transport channel on IDR failure\n\nIf transport channel setup succeeds but the following IDR insertion fails,\nthe error path destroys the transport device and frees the channel info\nwithout invoking the transport cleanup callback.\n\nCall chan_free() before destroying the device so transport specific\nresources such as IRQs, mailbox channels and mapped shared memory are\nreleased consistently with the normal teardown path."
}
],
"lastModified": "2026-09-17T17:18:02.840",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}