---
id: CVE-2026-93091
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  firmware: arm_scmi: Quiesce notifications before teardown

  scmi_notification_exit() clears and releases the notification instance,
  but transport callbacks can still del…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  firmware: arm_scmi: Quiesce notifications before teardown

  scmi_notification_exit() clears and releases the notification instance,
  but transport callbacks can still del…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 1e7cbfaa66d39e78bd24df0c78b55df68176b59e <
    6778bcabd2e0c32f73476f0bc6369013692540be
  - >-
    Linux >= 1e7cbfaa66d39e78bd24df0c78b55df68176b59e <
    2aac23bc0a79af41104d99823bb250fae92ba144
  - >-
    Linux >= 1e7cbfaa66d39e78bd24df0c78b55df68176b59e <
    5e30d3d16d1a9e599be4dcea872874e65e2c277b
  - >-
    Linux >= 1e7cbfaa66d39e78bd24df0c78b55df68176b59e <
    8e49055d0d495c9c07575ad8e111d9eaf0efb13f
  - Linux 5.15
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:18:03.063'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93091'
references:
  - url: 'https://git.kernel.org/stable/c/2aac23bc0a79af41104d99823bb250fae92ba144'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/5e30d3d16d1a9e599be4dcea872874e65e2c277b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/6778bcabd2e0c32f73476f0bc6369013692540be'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8e49055d0d495c9c07575ad8e111d9eaf0efb13f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-17T16:21:47.760Z'
epss: 0.00168
epssPercentile: 0.06494
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

firmware: arm_scmi: Quiesce notifications before teardown

scmi_notification_exit() clears and releases the notification instance,
but transport callbacks can still deliver incoming notifications until
the TX/RX channels are freed. During remove, an RX interrupt in that
window can enter scmi_notify() while notification state is being torn
down and then dereference freed memory. The same ordering exists on the
probe error path after notification initialization.

The notification late-init worker has a separate lifetime issue: protocol
event registration queues ni->init_work on the system workqueue, so
destroying ni->notify_wq does not drain that work. If the devres group is
released while init_work is still pending or running, the late-init worker
can dereference the freed notification instance.

Quiesce the notification core before TX/RX channels are torn down, then
clean up the channels before releasing the notification core resources.
Use disable_work_sync() so future late-init queueing is rejected and any
already queued or running late-init work has completed before channel
teardown starts.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
