Impact
The vulnerability originates in the Linux kernel’s serial core driver where a fallible allocation of UART port structures is performed after the console has already been registered. If the tty_groups or name allocation fails, the driver unwinds the port while the console remains registered, resulting in a null dereference in the PL011 console path or a KASAN use‑after‑free in the i.MX console path. This memory corruption can allow an attacker to trigger a kernel panic or potentially execute arbitrary code with kernel privileges, compromising the confidentiality, integrity, and availability of the affected system.
Affected Systems
This defect exists in the generic Linux kernel code; specific affected kernel releases are not provided by the CNA. The bug manifests during console or UART port initialization, which can occur at boot or when a console driver is bound dynamically.
Risk and Exploitability
The EPSS score is reported as less than 1 % and the vulnerability is not listed in the CISA KEV catalog. The impact is a Use‑After‑Free that can be exploited if allocation failures occur during port registration. Attackers would need to trigger a failed allocation on a UART console; the precise vector is not explicitly documented but is likely linked to boot or dynamic driver loading. Because the vulnerability can lead to code execution, the risk remains high despite the low EPSS probability, and immediate remediation is advised.
OpenCVE Enrichment