CVE-2026-93084

Published: Set 17, 2026 Last Modified: Set 17, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

In the Linux kernel, the following vulnerability has been resolved:

firmware: arm_scmi: Drop handle on protocol bind failures

The SCMI bus notifier acquires an SCMI handle when the driver core emits
BUS_NOTIFY_BIND_DRIVER, before invoking the protocol driver probe
callback. The protocol probe path only checks whether sdev->handle is
set.

If device_link_add() fails after the handle has been acquired, the
protocol device can still bind with a valid handle but without the
dependency link to the SCMI parent. A concurrent parent unbind can then
miss the child and tear down the SCMI instance while the child still
holds a handle into it.

If the protocol driver probe later fails, for example with
-EPROBE_DEFER, the driver core emits BUS_NOTIFY_DRIVER_NOT_BOUND rather
than BUS_NOTIFY_UNBOUND_DRIVER. The SCMI notifier only released the
handle on BUS_NOTIFY_UNBOUND_DRIVER, so each failed protocol-device bind
leaked the SCMI instance users refcount and left sdev->handle set after
the failed probe.

Make the link helper report failure and drop the acquired handle if the
link cannot be created. Also handle BUS_NOTIFY_DRIVER_NOT_BOUND in the
same cleanup path used for unbind so failed probes balance the earlier
BUS_NOTIFY_BIND_DRIVER acquisition.

https://git.kernel.org/stable/c/0f860db24ee95e5da4866303a35e55098b9641b3
https://git.kernel.org/stable/c/77d2985d1e80e67f32026fc03e975c4c83cc543d
https://git.kernel.org/stable/c/a54dc23e8bd2246c28eafffa60b4634f0d1a11cc
https://git.kernel.org/stable/c/df273eced7cec550465fd1bb82a5d2c3c7d3c437
https://git.kernel.org/stable/c/e3a5c30d233ca5d3e799a80da806554c703bda13