Impact
The i.MX UART driver in the Linux kernel publishes a reference to a UART port in the imx_uart_ports[] table before completing the device initialization. If the addition fails or the port is later removed, the table retains a pointer to freed memory. This dangling pointer can be reused by a subsequent probe through stale table entries. The result is kernel memory corruption, which could lead to privilege escalation or system instability.
Affected Systems
All Linux kernel builds that ship the i.MX UART driver with console support are affected. This includes ARM i.MX SoCs such as i.MX6UL and other variants, as well as virtual machine images that emulate these platforms. Embedded development boards and any system that loads this driver while console UARTs are active may also be impacted.
Risk and Exploitability
The flaw carries a CVSS score of 6.3, indicating moderate severity. The EPSS score is below 1 %, suggesting a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Exploitation would likely require privileged access to manipulate UART sysfs entries or to unbind and rebind UART devices while a console remains active. If successfully triggered, the dangling pointer could corrupt kernel memory, giving an attacker elevated privileges or allowing a denial‑of‑service.
OpenCVE Enrichment
Debian DSA