CVE-2026-93082: firmware: arm_scmi: Unwind P2A receiver mailbox setup failure

Published Sep 17, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

firmware: armscmi: Unwind P2A receiver mailbox setup failure

mailboxchansetup() can request an additional P2A receiver channel after successfully acquiring the primary P2A channel. If that later request fails, the function returns immediately and leaves the primary channel allocated.

Unwind the primary mailbox channel before returning the error so probe deferral or other setup failures do not leave the channel busy for later probe attempts.

Event History

Sep 17, 2026
CVE Published
via MITRE·04:11 PM
Data Sourced
via MITRE·04:11 PM
Description

Frequently Asked Questions

1

What conditions trigger the channel leak?

The leak occurs when mailbox_chan_setup() successfully acquires the primary P2A channel, then fails while requesting an additional P2A receiver channel. This can happen during probe deferral or other mailbox setup failures.

2

What is the operational impact of a failed setup attempt?

The primary P2A mailbox channel remains allocated and busy after the failure. Later probe attempts may be unable to acquire that channel.

3

What does the fix change?

The fix releases the primary mailbox channel before returning an error when setup of the additional P2A receiver channel fails.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203