Description
In the Linux kernel, the following vulnerability has been resolved:

serial: core: do fallible allocations before the console can be registered

serial_core_add_one_port() allocates uport->tty_groups after
uart_configure_port(), which may register the console. If the allocation
fails, the driver unwinds the port while its console remains registered.
The earlier uport->name allocation has a related failure path that leaves
state->uart_port linked to a port being freed.

Failslab reproduced a NULL dereference in PL011 console output and a KASAN
use-after-free in i.MX console output after failed binds.

Allocate the name and tty_groups before linking the port and configuring
it. Reserve space for the optional driver attribute group because
config_port() may populate uport->attr_group during configuration.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use‑after‑free leading to kernel crash or potential code execution
Action: Patch ASAP
AI Analysis

Impact

The vulnerability originates in the Linux kernel’s serial core driver where a fallible allocation of UART port structures is performed after the console has already been registered. If the tty_groups or name allocation fails, the driver unwinds the port while the console remains registered, resulting in a null dereference in the PL011 console path or a KASAN use‑after‑free in the i.MX console path. This memory corruption can allow an attacker to trigger a kernel panic or potentially execute arbitrary code with kernel privileges, compromising the confidentiality, integrity, and availability of the affected system.

Affected Systems

This defect exists in the generic Linux kernel code; specific affected kernel releases are not provided by the CNA. The bug manifests during console or UART port initialization, which can occur at boot or when a console driver is bound dynamically.

Risk and Exploitability

The EPSS score is reported as less than 1 % and the vulnerability is not listed in the CISA KEV catalog. The impact is a Use‑After‑Free that can be exploited if allocation failures occur during port registration. Attackers would need to trigger a failed allocation on a UART console; the precise vector is not explicitly documented but is likely linked to boot or dynamic driver loading. Because the vulnerability can lead to code execution, the risk remains high despite the low EPSS probability, and immediate remediation is advised.

Generated by OpenCVE AI on September 19, 2026 at 04:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to the most recent release that contains the commit correcting allocation ordering in serial_core_add_one_port and then reboot the system.
  • After the reboot, verify that the console initialization succeeds and that no KASAN or null dereference warnings appear in kernel logs.
  • If a patch is not yet available for your distribution, temporarily disable the affected UART console drivers via sysfs or during kernel configuration until a fixed kernel version can be deployed.

Generated by OpenCVE AI on September 19, 2026 at 04:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: serial: core: do fallible allocations before the console can be registered serial_core_add_one_port() allocates uport->tty_groups after uart_configure_port(), which may register the console. If the allocation fails, the driver unwinds the port while its console remains registered. The earlier uport->name allocation has a related failure path that leaves state->uart_port linked to a port being freed. Failslab reproduced a NULL dereference in PL011 console output and a KASAN use-after-free in i.MX console output after failed binds. Allocate the name and tty_groups before linking the port and configuring it. Reserve space for the optional driver attribute group because config_port() may populate uport->attr_group during configuration.
Title serial: core: do fallible allocations before the console can be registered
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:49.687Z

Reserved: 2026-09-11T19:38:34.804Z

Link: CVE-2026-90337

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:32.290

Modified: 2026-09-17T17:17:32.290

Link: CVE-2026-90337

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T06:45:16Z

Weaknesses