CVE-2026-93082

NameCVE-2026-93082
DescriptionIn the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Unwind P2A receiver mailbox setup failure mailbox_chan_setup() can request an additional P2A receiver channel after successfully acquiring the primary P2A channel. If that later request fails, the function returns immediately and leaves the primary channel allocated. Unwind the primary mailbox channel before returning the error so probe deferral or other setup failures do not leave the channel busy for later probe attempts.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-6528-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
linux (PTS)bookworm6.1.176-1fixed
bookworm (security)6.1.187-1fixed
trixie6.12.107-1vulnerable
trixie (security)6.12.111-1fixed
forky7.2.8-1fixed
sid7.2.9-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
linuxsourcebookworm(not affected)
linuxsourcetrixie6.12.111-1DSA-6528-1
linuxsource(unstable)7.2.6-1

Notes

[bookworm] - linux <not-affected> (Vulnerable code not present)
https://git.kernel.org/linus/f3e3773c4e5e96549d7540d8ddeb4fcd534f6f1d (7.3-rc1)

Search for package or bug name: Reporting problems