Junglewise Threat Intelligence

CVE-2025-39724: Linux Kernel 8250 serial driver race condition in UART startup

CVE-2025-39724 · Severity: medium · CVSS 5.5 · Published 2025-09-05

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's serial port driver can cause a system crash (kernel panic) under specific hardware configurations. This occurs when the system attempts to initialize certain serial communication hardware while another process is simultaneously accessing it. An exploit of this flaw would result in a complete denial of service, forcing the system to reboot and potentially disrupting operations or data processing.

Technical details

A race condition exists in the serial8250_do_startup() function of the Linux kernel's 8250 serial driver. When the PSLVERR_RESP_EN parameter is enabled, the hardware generates an error response if an empty Receive Buffer Register (RBR) is read while the FIFO is enabled. During startup, dw8250_check_lcr() may invoke dw8250_force_idle() if the UART is busy (e.g., due to printk() on another CPU), leading to a sequence that enables the FIFO and subsequently reads the empty RBR. This satisfies the PSLVERR trigger condition and results in a kernel panic. The fix involves moving the Line Control Register (LCR) write operation under the port lock to ensure atomic initialization.

Affected products

  • Linux Linux Kernel 3.10.48 to 3.11, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.44, 6.13 to 6.16.4

Timeline

  • 2025-07-23: other: Patch submitted by developer
  • 2025-09-05: advisory: CVE-2025-39724 published

References

Related threats