Missing Release of Resource after Effective Lifetime in Linux kernel - CVE-2026-93082
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to failure to release an allocated mailbox channel in mailbox_chan_setup() in the ARM SCMI mailbox transport when requesting an additional P2A receiver mailbox channel after acquiring the primary channel. A local user can trigger a failure in the additional channel request to cause a denial of service.