Description
In the Linux kernel, the following vulnerability has been resolved:

tty: clear cdev pointer after cdev_add() failure

tty_cdev_add() drops the cdev reference when cdev_add() fails, but
leaves driver->cdevs[index] pointing to freed memory.
tty_unregister_device() later passes that stale pointer to cdev_del(),
causing a use-after-free.

Clear the slot after dropping the reference.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption that may enable privilege escalation
Action: Patch
AI Analysis

Impact

The flaw occurs when tty_cdev_add() drops a reference to a character device but leaves the driver's internal array pointing to freed memory. When tty_unregister_device() later attempts to delete that stale pointer, a use‑after‑free is triggered inside the kernel, potentially corrupting memory. The resulting fault could crash the kernel, and based on typical use‑after‑free semantics, it is inferred that a locally privileged attacker who can influence the freed structure may be able to execute arbitrary code at kernel level, leading to privilege escalation.

Affected Systems

The vulnerability exists in the Linux kernel. All kernel builds that lack the patch are potentially affected; no specific version list is provided in the CVE data.

Risk and Exploitability

The EPSS score is less than 1 %, indicating a low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Although the CVSS score is not supplied, the kernel‑level use‑after‑free implies high severity. The likely attack vector involves a local attacker with the ability to load or manipulate tty drivers to trigger the fault.

Generated by OpenCVE AI on September 19, 2026 at 04:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update your Linux kernel to a version that contains the fix for CVE-2026-90334.
  • If an immediate kernel upgrade is not possible, limit access to tty character devices that could trigger the failure condition until the patch is applied.
  • Monitor system logs and kernel messages for indications of panics or issues related to tty device deletions and confirm that driver structures no longer contain stale pointers.

Generated by OpenCVE AI on September 19, 2026 at 04:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: tty: clear cdev pointer after cdev_add() failure tty_cdev_add() drops the cdev reference when cdev_add() fails, but leaves driver->cdevs[index] pointing to freed memory. tty_unregister_device() later passes that stale pointer to cdev_del(), causing a use-after-free. Clear the slot after dropping the reference.
Title tty: clear cdev pointer after cdev_add() failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:47.462Z

Reserved: 2026-09-11T19:38:34.803Z

Link: CVE-2026-90334

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:31.937

Modified: 2026-09-17T17:17:31.937

Link: CVE-2026-90334

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:30:06Z

Weaknesses