SB20260918221 - Use-after-free in Linux kernel firmware arm_scmi driver
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-92490)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to trigger a use-after-free condition.
The vulnerability exists due to use-after-free in the SCMI driver registration handling in scmi_driver_register() when driver registration fails. A local user can cause a driver registration failure and subsequently trigger request matching or SCMI device creation to trigger a use-after-free condition.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/06e65e07a1bcb39a1ebc8bb89a981f8e07900497
- https://git.kernel.org/stable/c/4520d4a1db37198756ad23568e36cdf091b6ffff
- https://git.kernel.org/stable/c/524e57035af2d32498af9dd8fa6fdc92fcc8f80a
- https://git.kernel.org/stable/c/9f7cd6a62aa754ed6b48cbd5d50de40add1bcc86
- https://git.kernel.org/stable/c/a76b20b1f03099204db29b90e1024fe1c2b2cdd7