CVE-2026-93081
CVE CVE-2026-93081EUVD EUVD-2026-82191Published 2026-09-17T16:11:01.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix SCMI device destroy lifetimes scmi_child_dev_find() drops the reference returned by device_find_child() before returning the scmi_device pointer. A concurrent unregister can then release the device while the destroy path is still using the returned pointer. Make the lookup helper return the device_find_child() reference and keep it until scmi_device_destroy() has finished unregistering the child. Also split device_unregister() in __scmi_device_destroy() so the SCMI bus ID is not made reusable until after device_del() has removed the old scmi_dev.N name from sysfs. This avoids a new SCMI device reusing the same ID while the old device is still registered. The final device release callback is also a possible cleanup path when SCMI children are deleted by driver core recursion rather than __scmi_device_destroy(). Release the SCMI bus ID from a common helper used by destroy, register-failure and final-release paths, and clear scmi_dev->id after freeing it so the final release cannot free the same ID again.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 6.6.90 <6.7; patch: 0; 6.1.138 <6.2; 969d8beaa2e374387bf9aa5602ef84fc50bb48d8; 91ff1e9652fb9beb0174267d6bb38243dff211bb; 5.15.182 <5.16; 2fbf6c9695ad9f05e7e5c166bf43fac7cb3276b3; 6.14.6 <6.15; 6.15; 9ca67840c0ddf3f39407339624cef824a4f27599 <6abe8fe36b29ff51d1a42c2f338972883f4751a5; 9ca67840c0ddf3f39407339624cef824a4f27599 <c59b3393df1348a12308aaabd5fbc58ed6b21cf5; patch: 7.3-rc1; 6.12.28 <6.13; patch: 7.2.6; ff4273d47da81b95ed9396110bcbd1b7b7470fe8; 8a8a3547d5c4960da053df49c75bf623827a25da
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.