CVE-2026-89512

medium

Description

In the Linux kernel, the following vulnerability has been resolved: remoteproc: scp: Fix device reference leak on failed lookup Make sure to drop the reference taken to the SCP device when attempting to look up its driver data before the driver has been bound. Note that holding a reference to a device does not prevent its driver data from going away.

References

https://git.kernel.org/stable/c/f794c930d8238e370fd61fcb12cc301ae098231b

https://git.kernel.org/stable/c/c7e32814a6bf20f792d05f0bc9f94f0606311bc6

https://git.kernel.org/stable/c/440bcb0948a12c9104b6dcca99a2cfb0db49b22a

https://git.kernel.org/stable/c/22f9efb3ae07f966a1901d929d16df1388cce65c

Details

Source: Mitre, NVD

Published: 2026-09-11

Updated: 2026-09-11

Risk Information

CVSS v2

Base Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.002