Description
In the Linux kernel, the following vulnerability has been resolved:

serial: imx: serialize imx_uart_ports[] lifetime

imx_uart_probe() publishes its devm-allocated port in imx_uart_ports[]
before uart_add_one_port() because console setup uses the table. The entry
is not cleared when adding the port fails or after removal, leaving a
dangling pointer.

A sibling probe can register the shared console through that stale entry.
This was reproduced under KASAN on QEMU mcimx6ul-evk by unbinding a
sibling UART, unbinding the console UART and rebinding the sibling.

Keep the entry valid through uart_remove_one_port(), then clear it. Protect
port addition and removal together with their table updates so sibling
operations cannot interleave. Reject an occupied slot rather than
clobbering an active port during a duplicate-line probe.
Published: 2026-09-11
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption
Action: Apply kernel update
AI Analysis

Impact

The i.MX UART driver in the Linux kernel publishes a reference to a UART port in the imx_uart_ports[] table before completing the device initialization. If the addition fails or the port is later removed, the table retains a pointer to freed memory. This dangling pointer can be reused by a subsequent probe through stale table entries. The result is kernel memory corruption, which could lead to privilege escalation or system instability.

Affected Systems

All Linux kernel builds that ship the i.MX UART driver with console support are affected. This includes ARM i.MX SoCs such as i.MX6UL and other variants, as well as virtual machine images that emulate these platforms. Embedded development boards and any system that loads this driver while console UARTs are active may also be impacted.

Risk and Exploitability

The flaw carries a CVSS score of 6.3, indicating moderate severity. The EPSS score is below 1 %, suggesting a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Exploitation would likely require privileged access to manipulate UART sysfs entries or to unbind and rebind UART devices while a console remains active. If successfully triggered, the dangling pointer could corrupt kernel memory, giving an attacker elevated privileges or allowing a denial‑of‑service.

Generated by OpenCVE AI on September 15, 2026 at 19:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a version that implements cleanup of imx_uart_ports[] before removal.
  • If a patch is not yet available, remove the console=uart parameter from the kernel command line or disable UART console support in the configuration.
  • Restrict access to UART device sysfs entries by tightening file permissions or applying SELinux/AppArmor policies to after applying the patch or configuration changes to clear any stale table entries.

Generated by OpenCVE AI on September 15, 2026 at 19:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 12 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H'}

threat_severity

Moderate


Sat, 12 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: serial: imx: serialize imx_uart_ports[] lifetime imx_uart_probe() publishes its devm-allocated port in imx_uart_ports[] before uart_add_one_port() because console setup uses the table. The entry is not cleared when adding the port fails or after removal, leaving a dangling pointer. A sibling probe can register the shared console through that stale entry. This was reproduced under KASAN on QEMU mcimx6ul-evk by unbinding a sibling UART, unbinding the console UART and rebinding the sibling. Keep the entry valid through uart_remove_one_port(), then clear it. Protect port addition and removal together with their table updates so sibling operations cannot interleave. Reject an occupied slot rather than clobbering an active port during a duplicate-line probe.
Title serial: imx: serialize imx_uart_ports[] lifetime
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:46:47.250Z

Reserved: 2026-09-11T19:38:34.761Z

Link: CVE-2026-89740

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:20:04.597

Modified: 2026-09-11T20:20:04.597

Link: CVE-2026-89740

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:47Z

Links: CVE-2026-89740 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:30:12Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference