CVE-2026-93089

Source
https://cve.org/CVERecord?id=CVE-2026-93089
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93089.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93089
Downstream
Published
2026-09-17T16:11:05Z
Modified
2026-09-18T03:48:44Z
Summary
firmware: arm_scmi: Free transport channel on IDR failure
Details

In the Linux kernel, the following vulnerability has been resolved:

firmware: arm_scmi: Free transport channel on IDR failure

If transport channel setup succeeds but the following IDR insertion fails, the error path destroys the transport device and frees the channel info without invoking the transport cleanup callback.

Call chan_free() before destroying the device so transport specific resources such as IRQs, mailbox channels and mapped shared memory are released consistently with the normal teardown path.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93089.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
05a2801d8b90c1b5159618d4bd3a3c65d60f3ff1
Fixed
ae7980c9af698d0a7e6790d49249abc71f0fc304
Fixed
de0a4c103740cf54cf77370d47e03c9aa51aa5ee
Fixed
d7c60c0fe2bd452b56fe07947842d64da61b7290
Fixed
fbaebd380caa4e1cec9306ca00231da6518a123f
Fixed
d72e7e5f24687c0490aabf317653caffe0447aeb

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93089.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.3.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93089.json"