Impact
The vulnerability lies in uart_register_driver() not clearing the drv->state and drv->tty_driver pointers when tty_alloc_driver() or tty_register_driver() fails, leaving them pointing to freed memory. If a driver uses these pointers as an "already registered" flag, the kernel can skip re‑registration and pass a dangling pointer to uart_add_one_port(). This use‑after‑free scenario can allow an attacker to corrupt kernel memory or execute arbitrary code with kernel privileges, or cause a denial of service by crashing the device.
Affected Systems
All Linux kernel builds that include the serial core UART subsystem are affected, regardless of specific version number. The flaw was discovered on QEMU raspi1ap and applies to any configuration that loads or probes PL011 or similar UART drivers.
Risk and Exploitability
The CVSS baseline for this flaw is not listed, but the EPSS score is below 1%, and it is not in the CISA KEV catalog, indicating a low current exploitation probability. However, the impact of a successful exploit is severe, giving kernel‑level code execution or service disruption. Attackers would need local or physical access that permits loading or re‑initializing a UART driver, which is typically restricted to privileged users or hardware developers.
OpenCVE Enrichment