Double free in Linux kernel - CVE-2026-92506
Published: September 18, 2026
Vulnerability identifier: #VU151007
CSH Severity: Low
CVSS v4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-92506
CWE-ID: CWE-415
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a double free in scmi_protocol_device_unrequest() when two SCMI drivers for the same protocol unregister concurrently. A local user can trigger concurrent unregistration of the drivers to cause a denial of service.
Affected software
Linux kernel
How to mitigate CVE-2026-92506
Install security update from vendor's repository.
External References
- https://git.kernel.org/stable/c/1c35915eaaa81a12340c838c5c2ccb02be2194c3
- https://git.kernel.org/stable/c/21d35c5f46e99e9047bb9ded3ecb5ab440dd75b3
- https://git.kernel.org/stable/c/2c4097e6c4aed276c5e9ec2ab331ab397ea780bf
- https://git.kernel.org/stable/c/2ff7713b7308cd6bea3328f7cd750b5eaab42af3
- https://git.kernel.org/stable/c/c3d4ef1c0ca6917aad6f1093b49f3932944a8c19