Answer in brief
CVE-2026-93091 records a Unknown severity vulnerability in firmware: arm_scmi: Quiesce notifications before teardown. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1e7cbfaa66d39e78bd24df0c78b55df68176b59e <6778bcabd2e0c32f73476f0bc6369013692540be || >=1e7cbfaa66d39e78bd24df0c78b55df68176b59e <2aac23bc0a79af41104d99823bb250fae92ba144 || >=1e7cbfaa66d39e78bd24df0c78b55df68176b59e <5e30d3d16d1a9e599be4dcea872874e65e2c277b || >=1e7cbfaa66d39e78bd24df0c78b55df68176b59e <8e49055d0d495c9c07575ad8e111d9eaf0efb13f | 6778bcabd2e0c32f73476f0bc6369013692540be, 2aac23bc0a79af41104d99823bb250fae92ba144, 5e30d3d16d1a9e599be4dcea872874e65e2c277b, 8e49055d0d495c9c07575ad8e111d9eaf0efb13f |
| Linux/Linuxgeneric | 5.15 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Quiesce notifications before teardown scmi_notification_exit() clears and releases the notification instance, but transport callbacks can still deliver incoming notifications until the TX/RX channels are freed. During remove, an RX interrupt in that window can enter scmi_notify() while notification state is being torn down and then dereference freed memory. The same ordering exists on the probe error path after notification initialization. The notification late-init worker has a separate lifetime issue: protocol event registration queues ni->init_work on the system workqueue, so destroying ni->notify_wq does not drain that work. If the devres group is released while init_work is still pending or running, the late-init worker can dereference the freed notification instance. Quiesce the notification core before TX/RX channels are torn down, then clean up the channels before releasing the notification core resources. Use disable_work_sync() so future late-init queueing is rejected and any already queued or running late-init work has completed before channel teardown starts.
Quoted source text, attributed separately from HOL analysis.