« Back to list

CVE-2026-93089

Status: ReceivedUnscored—

In the Linux kernel, the following vulnerability has been resolved:

firmware: arm_scmi: Free transport channel on IDR failure

If transport channel setup succeeds but the following IDR insertion fails, the error path destroys the transport device and frees the channel info without invoking the transport cleanup callback.

Call chan_free() before destroying the device so transport specific resources such as IRQs, mailbox channels and mapped shared memory are released consistently with the normal teardown path.

CVSS

NVD hasn't assigned a CVSS score to this CVE (common since the April 2026 policy change).

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2026-93089",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "05a2801d8b90c1b5159618d4bd3a3c65d60f3ff1",
              "lessThan": "ae7980c9af698d0a7e6790d49249abc71f0fc304",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "05a2801d8b90c1b5159618d4bd3a3c65d60f3ff1",
              "lessThan": "de0a4c103740cf54cf77370d47e03c9aa51aa5ee",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "05a2801d8b90c1b5159618d4bd3a3c65d60f3ff1",
              "lessThan": "d7c60c0fe2bd452b56fe07947842d64da61b7290",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "05a2801d8b90c1b5159618d4bd3a3c65d60f3ff1",
              "lessThan": "fbaebd380caa4e1cec9306ca00231da6518a123f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "05a2801d8b90c1b5159618d4bd3a3c65d60f3ff1",
              "lessThan": "d72e7e5f24687c0490aabf317653caffe0447aeb",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/firmware/arm_scmi/driver.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.3"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.3",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/firmware/arm_scmi/driver.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:18:02.840",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/ae7980c9af698d0a7e6790d49249abc71f0fc304",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d72e7e5f24687c0490aabf317653caffe0447aeb",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d7c60c0fe2bd452b56fe07947842d64da61b7290",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/de0a4c103740cf54cf77370d47e03c9aa51aa5ee",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fbaebd380caa4e1cec9306ca00231da6518a123f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_scmi: Free transport channel on IDR failure\n\nIf transport channel setup succeeds but the following IDR insertion fails,\nthe error path destroys the transport device and frees the channel info\nwithout invoking the transport cleanup callback.\n\nCall chan_free() before destroying the device so transport specific\nresources such as IRQs, mailbox channels and mapped shared memory are\nreleased consistently with the normal teardown path."
    }
  ],
  "lastModified": "2026-09-17T17:18:02.840",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}