Bug 2536232 (CVE-2026-93083)

Summary: CVE-2026-93083 kernel: firmware: arm_scmi: Unwind TX receiver mailbox setup failure
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: akhatavk, aos-team-art-private, asdas, dpaolell, jdelft, jupierce, lgarciaa, mbiarnes, ppalepu, ppostler, prdhamdh, rhel-process-autobot, sghai, sidsharm, suppawar, vlaad, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the `arm_scmi` firmware component of the Linux kernel. When the `mailbox_chan_setup()` function attempts to set up a unidirectional transmit (TX) receiver channel, it may fail to properly release the primary channel if the secondary channel request fails. This resource leak can leave the primary mailbox channel allocated and busy, potentially causing probe deferral or other setup failures, which could lead to a denial of service for affected system operations.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-09-17 17:01:27 UTC
In the Linux kernel, the following vulnerability has been resolved:

firmware: arm_scmi: Unwind TX receiver mailbox setup failure

mailbox_chan_setup() can request an additional unidirectional TX
receiver channel after successfully acquiring the primary channel. If
that second request fails, the function returns immediately and leaves
the primary channel allocated.

Unwind the primary mailbox channel before returning the error so probe
deferral or other setup failures do not leave the channel busy for later
probe attempts.