Linux Kernel SCMI Debug Initialization Fault Handling Vulnerability

Vulnerability

A vulnerability exists in the Linux kernel's SCMI (System Control and Management Interface) debug subsystem. When the debug subsystem fails to initialize, it results in a missing debug root and a NULL descriptor. This issue affects the SCMI debug helpers responsible for maintaining metrics counters, leading to improper handling of debug information. The vulnerability has been addressed in the Linux kernel stable tree.

Impact

The vulnerability could cause the SCMI debug subsystem to mismanage debug metrics, potentially obscuring important debugging information and complicating the diagnosis of issues within the SCMI framework.

Remediation

Users can upgrade to the latest version of the Linux kernel stable tree to address this vulnerability.

Added: Dec 4, 2025, 5:05 PM
Updated: Dec 4, 2025, 6:04 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
4.0
remediation
7.7
relevance
1.2
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.