{"id":"CVE-2026-92490","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_scmi: Unrequest devices if driver registration fails\n\nscmi_driver_register() requests protocol devices before registering the\ndriver","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_scmi: Unrequest devices if driver registration fails\n\nscmi_driver_register() requests protocol devices before registering the\ndriver. If driver_register()…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= d3cd7c525fd2ecce3a6c963f314969a54783d211 < 524e57035af2d32498af9dd8fa6fdc92fcc8f80a","Linux >= d3cd7c525fd2ecce3a6c963f314969a54783d211 < 06e65e07a1bcb39a1ebc8bb89a981f8e07900497","Linux >= d3cd7c525fd2ecce3a6c963f314969a54783d211 < a76b20b1f03099204db29b90e1024fe1c2b2cdd7","Linux >= d3cd7c525fd2ecce3a6c963f314969a54783d211 < 4520d4a1db37198756ad23568e36cdf091b6ffff","Linux >= d3cd7c525fd2ecce3a6c963f314969a54783d211 < 9f7cd6a62aa754ed6b48cbd5d50de40add1bcc86","Linux 6.3"],"published":"2026-09-17","updated":"2026-09-17","sourceUpdated":"2026-09-17T17:17:51.123","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92490","references":[{"url":"https://git.kernel.org/stable/c/06e65e07a1bcb39a1ebc8bb89a981f8e07900497","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4520d4a1db37198756ad23568e36cdf091b6ffff","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/524e57035af2d32498af9dd8fa6fdc92fcc8f80a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f7cd6a62aa754ed6b48cbd5d50de40add1bcc86","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a76b20b1f03099204db29b90e1024fe1c2b2cdd7","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-17T16:21:47.785Z","epss":0.00168,"epssPercentile":0.06477,"slug":"CVE-2026-92490","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_scmi: Unrequest devices if driver registration fails\n\nscmi_driver_register() requests protocol devices before registering the\ndriver. If driver_register() fails, those requests remain in the global\nIDR and retain pointers to the module's ID table. Once the failed module\nload releases that storage, later request matching or SCMI device creation\ncan dereference the stale pointers.\n\nUnrequest the complete protocol table before returning the registration\nfailure. At this point table registration succeeded, so every entry is\nowned by the current registration attempt.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}