Description
In the Linux kernel, the following vulnerability has been resolved:

tty: skip cdev_del() when no cdev is registered

TTY device registration can fail before a cdev is allocated.
Serial core keeps the port so setserial can still use it, and later
removal passes the NULL cdev slot to cdev_del(), causing a NULL-pointer
dereference.

Only delete the cdev when the slot is not NULL.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The kernel’s TTY subsystem can crash when a serial port that never successfully registered a character device is removed; the code attempts to dereference a NULL cdev pointer, triggering a null‑pointer dereference and a kernel panic. This results in a loss of system availability for the affected node.

Affected Systems

All Linux kernel installations that lack the patch introduced by commit 3dbf85ef40b6366ba15e882f7536cdc98bea579a and c3b5623fd97648f2747444aa8932ae604662df93 are vulnerable. The defect appears in the TTY core logic that handles serial port removal.

Risk and Exploitability

Based on the description, it is inferred that the vulnerability is local and requires an attacker to trigger the removal of an unregistered serial port. Because EPSS is below 1% and the issue is not in the CISA KEV catalog, the likelihood of exploitation is low. However, should an attacker succeed, the kernel crash would provide a denial of service.

Generated by OpenCVE AI on September 19, 2026 at 14:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that includes the commits 3dbf85ef40b6366ba15e882f7536cdc98bea579a or c3b5623fd97648f2747444aa8932ae604662df93
  • Reboot the system if the kernel change requires a full restart
  • Apply any vendor‑mandated security hardening for the TTY subsystem, such as restricting user access to serial device configuration tools

Generated by OpenCVE AI on September 19, 2026 at 14:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: tty: skip cdev_del() when no cdev is registered TTY device registration can fail before a cdev is allocated. Serial core keeps the port so setserial can still use it, and later removal passes the NULL cdev slot to cdev_del(), causing a NULL-pointer dereference. Only delete the cdev when the slot is not NULL.
Title tty: skip cdev_del() when no cdev is registered
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:48.127Z

Reserved: 2026-09-11T19:38:34.803Z

Link: CVE-2026-90335

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:32.073

Modified: 2026-09-17T17:17:32.073

Link: CVE-2026-90335

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:00:12Z

Weaknesses