Impact
The kernel’s TTY subsystem can crash when a serial port that never successfully registered a character device is removed; the code attempts to dereference a NULL cdev pointer, triggering a null‑pointer dereference and a kernel panic. This results in a loss of system availability for the affected node.
Affected Systems
All Linux kernel installations that lack the patch introduced by commit 3dbf85ef40b6366ba15e882f7536cdc98bea579a and c3b5623fd97648f2747444aa8932ae604662df93 are vulnerable. The defect appears in the TTY core logic that handles serial port removal.
Risk and Exploitability
Based on the description, it is inferred that the vulnerability is local and requires an attacker to trigger the removal of an unregistered serial port. Because EPSS is below 1% and the issue is not in the CISA KEV catalog, the likelihood of exploitation is low. However, should an attacker succeed, the kernel crash would provide a denial of service.
OpenCVE Enrichment