Impact
The flaw in the Linux kernel’s serial driver for qcom GENI devices allows a stale DMA completion interrupt to advance the transmit FIFO incorrectly. When the serial core flushes the transmit buffer after a DMA transfer but before the completion interrupt is handled, the remaining byte count (tx_remaining) still reflects the old transfer. If user space writes new data after the flush, the stale interrupt may advance the FIFO and discard those new bytes. This race condition can lose transmitted data or disrupt serial communication flow, potentially leading to degraded service or data integrity violations.
Affected Systems
The vulnerability affects any system running the Linux kernel that includes the qcom GENI serial driver. No specific kernel versions are listed in the CNA data, so all releases containing the unpatched qcom GENI logic are potentially affected.
Risk and Exploitability
The EPSS score is below 1% and the issue is not listed in the CISA KEV catalog, indicating a low probability of exploitation in the wild. However, the flaw requires the attacker to have access to the affected serial device, which could be provided by a local unprivileged user or a privileged process that can write to the UART. If forced, the race could be triggered to cause data loss or cause a service disruption. The official reference commits suggest that the fix is a kernel patch; therefore the risk is mitigated once the kernel is updated.
OpenCVE Enrichment
Debian DLA
Debian DSA