CVE-2026-98363: firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS
firmware: armscpi: reject DVFS OPP count above MAXDVFSOPPS
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Update scpi_dvfs_get_info() to reject zero or out-of-range opp_count values above MAX_DVFS_OPPS and return -EINVAL.
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Systems running the Linux kernel with ARM SCPI DVFS support are exposed when they obtain DVFS operating-point information from SCP firmware. The issue is triggered by an SCP firmware reply that reports an OPP count greater than MAX_DVFS_OPPS.
What does an attacker or faulty component need to do to trigger the flaw?
The SCP firmware must provide an out-of-range DVFS OPP count. The vulnerable kernel code trusts that count, reads beyond the fixed shared-memory OPP array, and uses the resulting data when sizing the OPP table.
What happens after the fix is applied?
The kernel rejects both zero and out-of-range OPP counts in a single validation check and returns -EINVAL. This prevents reading past the shared-memory OPP array and allocating an incorrectly sized OPP table.