Description
In the Linux kernel, the following vulnerability has been resolved:

serial: core: clear freed pointers on uart_register_driver() failure

uart_register_driver() leaves drv->state pointing to freed memory when
tty_alloc_driver() fails. If tty_register_driver() fails, drv->tty_driver
also retains a pointer after its reference is dropped.

Drivers that use drv->state as an "already registered" flag can then skip
registration on the next probe and pass the freed state to
uart_add_one_port().

This issue was found with failslab on QEMU's raspi1ap board by
failing registration and binding the PL011 port again.

Clear both pointers on their failure paths, as uart_unregister_driver()
already does.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel privilege escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability lies in uart_register_driver() not clearing the drv->state and drv->tty_driver pointers when tty_alloc_driver() or tty_register_driver() fails, leaving them pointing to freed memory. If a driver uses these pointers as an "already registered" flag, the kernel can skip re‑registration and pass a dangling pointer to uart_add_one_port(). This use‑after‑free scenario can allow an attacker to corrupt kernel memory or execute arbitrary code with kernel privileges, or cause a denial of service by crashing the device.

Affected Systems

All Linux kernel builds that include the serial core UART subsystem are affected, regardless of specific version number. The flaw was discovered on QEMU raspi1ap and applies to any configuration that loads or probes PL011 or similar UART drivers.

Risk and Exploitability

The CVSS baseline for this flaw is not listed, but the EPSS score is below 1%, and it is not in the CISA KEV catalog, indicating a low current exploitation probability. However, the impact of a successful exploit is severe, giving kernel‑level code execution or service disruption. Attackers would need local or physical access that permits loading or re‑initializing a UART driver, which is typically restricted to privileged users or hardware developers.

Generated by OpenCVE AI on September 19, 2026 at 04:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the uart_register_driver() pointer clearing fix.
  • Ensure driver code initializes drv->state and drv->tty_driver to NULL on registration failure and checks these pointers before use.
  • Disable or remove unused UART drivers from the build configuration to reduce the attack surface.

Generated by OpenCVE AI on September 19, 2026 at 04:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: serial: core: clear freed pointers on uart_register_driver() failure uart_register_driver() leaves drv->state pointing to freed memory when tty_alloc_driver() fails. If tty_register_driver() fails, drv->tty_driver also retains a pointer after its reference is dropped. Drivers that use drv->state as an "already registered" flag can then skip registration on the next probe and pass the freed state to uart_add_one_port(). This issue was found with failslab on QEMU's raspi1ap board by failing registration and binding the PL011 port again. Clear both pointers on their failure paths, as uart_unregister_driver() already does.
Title serial: core: clear freed pointers on uart_register_driver() failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:49.016Z

Reserved: 2026-09-11T19:38:34.803Z

Link: CVE-2026-90336

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:32.180

Modified: 2026-09-17T17:17:32.180

Link: CVE-2026-90336

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T05:30:17Z

Weaknesses