Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-93085— firmware: arm_scmi: Reject out of range DT protocol IDs

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,以下漏洞已得到修复: 固件:arm_scmi:拒绝范围外的 DT 协议 ID SCMI 消息头部中携带的 SCMI 协议 ID 受 限制。设备树(DT)解析路径在遇到超出该范围的协议 ID 时,仅记录错误日志,但随后仍继续处理这个无效值。 这使得一个格式错误的 32 位 DT 值能够传送到接收 8 位(u8)协议 ID 的辅助函数中,在那里它可能会被截断,或被误认为另一个协议。 在通道建立过程中,两个不同的超范围值还可以作为不同的 IDR 密钥使用,同时却映射(aliasing)到生成的 S

AI Predicted 3.1 Difficulty: Moderate EPSS 0.21% · P10

Affected Version Matrix 12

VendorProduct Version RangeStatus
Linux Linux 05a2801d8b90c1b5159618d4bd3a3c65d60f3ff1< 8eb2ab209570526728b35e39c4aecdb5099fbaf7 affected
05a2801d8b90c1b5159618d4bd3a3c65d60f3ff1< 5142fd31bd8c9aff9bad4f6e0cc20e9574f2cee1 affected
05a2801d8b90c1b5159618d4bd3a3c65d60f3ff1< e66756313d1b4eadd13f39a0aee9fc8773d4d375 affected
05a2801d8b90c1b5159618d4bd3a3c65d60f3ff1< 0b6e59eb885f985a5ea7beed385adfa9412b324d affected
05a2801d8b90c1b5159618d4bd3a3c65d60f3ff1< 59407ccb52130f2c81f4b3cbe4f14114afceb54f affected
6.3 affected
< 6.3 unaffected
6.6.157≤ 6.6.* unaffected
… +4 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93085

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
firmware: arm_scmi: Reject out of range DT protocol IDs
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Reject out of range DT protocol IDs SCMI protocol IDs carried in message headers are limited by MSG_PROTOCOL_ID_MASK. The DT parsing paths noticed protocol IDs outside that range, but only logged an error and then kept processing the invalid value. That lets a malformed 32-bit DT reg value reach helpers which take a u8 protocol ID, where it can be truncated and/or treated as a different protocol. For channel setup, two different out-of-range values can also be used as distinct IDR keys while aliasing the generated SCMI protocol identity. Skip DT protocol nodes whose reg value does not fit the SCMI protocol ID field before setting up channels or creating protocol devices.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 05a2801d8b90c1b5159618d4bd3a3c65d60f3ff1 ~ 8eb2ab209570526728b35e39c4aecdb5099fbaf7 -
Linux Linux 6.3 -

II. Public POCs for CVE-2026-93085

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93085

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-93085 (4)

Same Patch Batch · Linux · 2026-09-17 · 600 CVEs total

CVE-2026-92489 9.8 CRITICAL xfrm: Fix skb double-free in xfrm_dev_direct_output()
CVE-2026-90173 9.8 CRITICAL smb: smbdirect: free completion queues with ib_free_cq()
CVE-2026-90235 9.8 CRITICAL sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE
CVE-2026-90104 9.8 CRITICAL NFSv4.1: zero referring call lists before decoding
CVE-2026-90151 9.8 CRITICAL NFSv4: remove callback IDR entry on client allocation failure
CVE-2026-90110 9.4 CRITICAL inetpeer: randomize RB-tree node comparison using SipHash
CVE-2026-90230 9.1 CRITICAL nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate()
CVE-2026-90414 9.1 CRITICAL IB/isert: reject PDUs declaring more data than was received
CVE-2026-90413 9.1 CRITICAL IB/isert: reject login PDUs declaring more data than was received
CVE-2026-90367 8.8 HIGH wifi: mt76: mt7996: hold dev->mt76.mutex while disabling tx worker in SER
CVE-2026-90329 8.8 HIGH HID: synchronize input before cleaning up a failed probe
CVE-2026-93189 8.8 HIGH HID: core: quiesce input in hid_hw_stop() to prevent use-after-free
CVE-2026-90286 8.8 HIGH drm/amdgpu/gfx6: Use PFP on the compute queues too
CVE-2026-90357 8.8 HIGH wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement
CVE-2026-90240 8.8 HIGH iommu/vt-d: Flush context cache with correct SID when tearing down aliases
CVE-2026-93042 8.8 HIGH dmaengine: dw-edma: Terminate all descriptors without callbacks
CVE-2026-90256 8.8 HIGH Bluetooth: L2CAP: use proto_lock for l2cap_data to fix l2cap_disconn_ind
CVE-2026-90380 8.8 HIGH wifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete
CVE-2026-90381 8.8 HIGH wifi: mt76: fix handling channel context with different bands in mt76_switch_vif_chanctx()
CVE-2026-90425 8.8 HIGH iommu/tegra241-cmdqv: Require exactly one Stream ID for a vSID

Showing top 20 of 600 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-93085

No comments yet


Leave a comment