Description
In the Linux kernel, the following vulnerability has been resolved:

serial: qcom-geni: do not advance stale DMA completions

The qcom GENI serial DMA TX completion path advances the transmit fifo by
the number of bytes recorded in port->tx_remaining.

If uart_flush_buffer() runs after the hardware has completed a DMA
transfer but before the DMA completion interrupt has been handled, the
serial core resets the transmit fifo while port->tx_remaining still
describes the old DMA transfer.

A previous fix avoided advancing an empty fifo by checking that the fifo
length is at least tx_remaining. That still does not distinguish the old
DMA payload from new bytes written after the flush. If userspace writes
new data before the stale DMA completion interrupt is handled, the fifo
can again contain at least tx_remaining bytes and the stale completion
can advance and discard those new bytes.

Mark an in-flight DMA transfer stale when the transmit fifo is flushed.
The later completion still unprepares the original DMA mapping using the
saved length, but it no longer advances the transmit fifo.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Data Loss / Denial of Service
Action: Patch
AI Analysis

Impact

The flaw in the Linux kernel’s serial driver for qcom GENI devices allows a stale DMA completion interrupt to advance the transmit FIFO incorrectly. When the serial core flushes the transmit buffer after a DMA transfer but before the completion interrupt is handled, the remaining byte count (tx_remaining) still reflects the old transfer. If user space writes new data after the flush, the stale interrupt may advance the FIFO and discard those new bytes. This race condition can lose transmitted data or disrupt serial communication flow, potentially leading to degraded service or data integrity violations.

Affected Systems

The vulnerability affects any system running the Linux kernel that includes the qcom GENI serial driver. No specific kernel versions are listed in the CNA data, so all releases containing the unpatched qcom GENI logic are potentially affected.

Risk and Exploitability

The EPSS score is below 1% and the issue is not listed in the CISA KEV catalog, indicating a low probability of exploitation in the wild. However, the flaw requires the attacker to have access to the affected serial device, which could be provided by a local unprivileged user or a privileged process that can write to the UART. If forced, the race could be triggered to cause data loss or cause a service disruption. The official reference commits suggest that the fix is a kernel patch; therefore the risk is mitigated once the kernel is updated.

Generated by OpenCVE AI on September 19, 2026 at 07:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the qcom GENI serial DMA fix, using the commit hashes provided in the references for accurate patch application.
  • Ensure the kernel is rebuilt and tested in a staging environment before deploying the new kernel to production systems.
  • Verify that the system does not use the serial DMA path for critical services; if possible, disable qcom GENI DMA usage via device tree or boot parameters until the kernel is patched.

Generated by OpenCVE AI on September 19, 2026 at 07:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-365

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: serial: qcom-geni: do not advance stale DMA completions The qcom GENI serial DMA TX completion path advances the transmit fifo by the number of bytes recorded in port->tx_remaining. If uart_flush_buffer() runs after the hardware has completed a DMA transfer but before the DMA completion interrupt has been handled, the serial core resets the transmit fifo while port->tx_remaining still describes the old DMA transfer. A previous fix avoided advancing an empty fifo by checking that the fifo length is at least tx_remaining. That still does not distinguish the old DMA payload from new bytes written after the flush. If userspace writes new data before the stale DMA completion interrupt is handled, the fifo can again contain at least tx_remaining bytes and the stale completion can advance and discard those new bytes. Mark an in-flight DMA transfer stale when the transmit fifo is flushed. The later completion still unprepares the original DMA mapping using the saved length, but it no longer advances the transmit fifo.
Title serial: qcom-geni: do not advance stale DMA completions
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:28.552Z

Reserved: 2026-09-17T16:02:15.086Z

Link: CVE-2026-93123

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:07.020

Modified: 2026-09-17T17:18:07.020

Link: CVE-2026-93123

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:00:11Z

Weaknesses
  • CWE-365

    DEPRECATED: Race Condition in Switch