Executive brief
A security vulnerability has been identified in the Linux kernel's CAIF serial driver. This flaw could allow a local attacker to cause a system crash or potentially execute unauthorized actions by exploiting a timing issue when closing certain network connections. The issue specifically affects systems using the CAIF protocol, often used in cellular modem communications.
Technical details
A use-after-free (UAF) vulnerability exists in drivers/net/caif/caif_serial.c due to a race condition between ldisc_close() and caif_xmit(). The root cause is that tty_kref_put() is called in ldisc_close() while the network device is still active. If a packet transmission occurs via handle_tx() during this window, it may access the ser->tty pointer after the tty object has been freed. An attacker can trigger this by initiating a close operation while simultaneously sending packets. The fix involves deferring the tty reference release to ser_release() after the network device has been successfully unregistered.
Affected products
- Linux Linux Kernel Fixed in 308e7e4d0a846359685f40aade023aee7b27284c and related stable backports
Timeline
- 2026-02-10: patched: Initial fix committed to mainline kernel
- 2026-05-27: disclosed: CVE published
References
- https://git.kernel.org/stable/c/308e7e4d0a846359685f40aade023aee7b27284c
- https://git.kernel.org/stable/c/331e2b7051635780edea248dd08ae2026c126f4a
- https://git.kernel.org/stable/c/40962f2bf8cdba63af23aec95ad3f49b689e58e2
- https://git.kernel.org/stable/c/4e63d6f68544ae5269ac9735ae5b69b59b5b8725
- https://git.kernel.org/stable/c/52731ef4438155cea782fac74e547a327ab9e7c5
- https://git.kernel.org/stable/c/5e266ba8d330d3b8e5bc198f238cd8901826cfa1
- https://git.kernel.org/stable/c/c8c197aaa56b25a2d54f3aa07e27e228d6c08546