Executive brief
A vulnerability in the Zephyr operating system's serial port driver can cause devices to freeze or become unresponsive. This occurs when a connected hardware device (like a Bluetooth module) stops signaling that it is ready to receive data, causing the system to enter an infinite loop. This results in a total loss of availability for the affected device, potentially disrupting communications or critical operations until the system is reset.
Technical details
An unbounded software loop exists in the pl011_irq_tx_enable() function within drivers/serial/uart_pl011.c. When CTS hardware flow control is enabled and a wired serial peer de-asserts the CTS signal, the controller stops draining the TX FIFO. Because pl011_fifo_fill() returns 0 while pending data remains, the TX interrupt is never disabled, causing the calling thread to spin indefinitely (CWE-835). This stalls the executing context and transport layer, such as the Bluetooth HCI H4 driver. The issue was introduced in commit b783bc8448ef and is fixed by breaking the loop when CTS is blocking and utilizing the CTS modem-status interrupt to resume.
Affected products
- Zephyr Project Zephyr RTOS v4.1.0 through v4.4.0
Timeline
- 2025-02-10: other: Vulnerability introduced in commit b783bc8448ef
- 2026-06-17: other: Embargo date
- 2026-06-24: disclosed: Advisory published
- 2026-06-24: patched: Fix merged into main branch