CVE-2026-93081
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix SCMI device destroy lifetimes scmi_child_dev_find() drops the reference returned by device_find_child() before returning the scmi_device pointer. A concurrent unregister can then release the device while the destroy path is still using the returned pointer. Make the lookup helper return the device_find_child() reference and keep it until scmi_device_destroy() has finished unregistering the child. Also split device_unregister() in __scmi_device_destroy() so the SCMI bus ID is not made reusable until after device_del() has removed the old scmi_dev.N name from sysfs. This avoids a new SCMI device reusing the same ID while the old device is still registered. The final device release callback is also a possible cleanup path when SCMI children are deleted by driver core recursion rather than __scmi_device_destroy(). Release the SCMI bus ID from a common helper used by destroy, register-failure and final-release paths, and clear scmi_dev->id after freeing it so the final release cannot free the same ID again.
Affected versions
Linux kernel versions
5.15.182,
6.1.138,
6.6.90,
6.12.28,
6.14.6,
6.15
and later are affected. Fixed in
7.2.6,
7.3-rc1
and their respective stable series.
References
2 totalFrequently asked questions
-
What is CVE-2026-93081?
CVE-2026-93081 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 5.15.182 onward and has been patched in 7.2.6 and 7.3-rc1. CVE-2026-93081 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2026-93081?
Yes. CVE-2026-93081 has been patched. Fixed versions include 7.2.6 and 7.3-rc1. If you are running Linux kernel 5.15.182 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-93081 actively exploited?
No. CVE-2026-93081 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.