SB20260918132 - Improper Validation of Specified Quantity in Input in Linux kernel firmware arm_scmi driver



SB20260918132 - Improper Validation of Specified Quantity in Input in Linux kernel firmware arm_scmi driver

Published: September 18, 2026

Security Bulletin ID SB20260918132
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-93085)

CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause SCMI protocol ID truncation or aliasing.

The vulnerability exists due to improper validation of specified quantities in input in the SCMI device tree parsing paths when processing a malformed 32-bit device tree reg value. A local user can provide an out-of-range protocol ID to cause SCMI protocol ID truncation or aliasing.


Remediation

Install update from vendor's website.