CVE-2026-93089
Published Sep 17, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Free transport channel on IDR failure If transport channel setup succeeds but the following IDR insertion fails, the error path destroys the transport device and frees the channel info without invoking the transport cleanup callback. Call chan_free() before destroying the device so transport specific resources such as IRQs, mailbox channels and mapped shared memory are released consistently with the normal teardown path.
Is your site exposed to CVE-2026-93089?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/ae7980c9af698d0a7e6790d49249abc71f0fc304
https://git.kernel.org/stable/c/d72e7e5f24687c0490aabf317653caffe0447aeb
https://git.kernel.org/stable/c/d7c60c0fe2bd452b56fe07947842d64da61b7290
https://git.kernel.org/stable/c/de0a4c103740cf54cf77370d47e03c9aa51aa5ee
https://git.kernel.org/stable/c/fbaebd380caa4e1cec9306ca00231da6518a123f
Frequently Asked Questions
What is CVE-2026-93089? +
In the Linux kernel, the following vulnerability has been resolved:
firmware: arm_scmi: Free transport channel on IDR failure
If transport channel setup succeeds but the following IDR insertion fails,
the error path destroys the transport device and frees the channel info
without invoking the transport cleanup callback.
Call chan_free() before destroying the device so transport specific
resources such as IRQs, mailbox channels and mapped shared memory are
released consistently with the normal teardown path.
How do I check if I'm vulnerable to CVE-2026-93089? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.