SB20260918132 - Improper Validation of Specified Quantity in Input in Linux kernel firmware arm_scmi driver
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-93085)
CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause SCMI protocol ID truncation or aliasing.
The vulnerability exists due to improper validation of specified quantities in input in the SCMI device tree parsing paths when processing a malformed 32-bit device tree reg value. A local user can provide an out-of-range protocol ID to cause SCMI protocol ID truncation or aliasing.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0b6e59eb885f985a5ea7beed385adfa9412b324d
- https://git.kernel.org/stable/c/5142fd31bd8c9aff9bad4f6e0cc20e9574f2cee1
- https://git.kernel.org/stable/c/59407ccb52130f2c81f4b3cbe4f14114afceb54f
- https://git.kernel.org/stable/c/8eb2ab209570526728b35e39c4aecdb5099fbaf7
- https://git.kernel.org/stable/c/e66756313d1b4eadd13f39a0aee9fc8773d4d375