Executive brief
A vulnerability in the Linux kernel's serial port driver could lead to system instability or crashes. When certain hardware components fail to initialize correctly, the system may continue to reference memory that has already been cleared. This could be used by a local attacker to cause a denial-of-service condition or potentially execute unauthorized actions on the system.
Technical details
A use-after-free (UAF) vulnerability exists in the drivers/tty/serial/8250/8250_dw.c component of the Linux kernel. During the dw8250_probe() process, the driver registers an 8250 port but fails to unregister it if a subsequent clk_notifier_register() call fails. Because the driver's devm-allocated data is freed upon probe failure while the port remains registered and maintains references to that data (via private_data and serial_in/out callbacks), any subsequent access to the port results in a UAF hazard. This can be triggered during device binding/unbinding or through specific hardware error states. Patches have been released across multiple stable kernel branches to ensure the port is properly unregistered on the error path.
Affected products
- Linux Linux Kernel 5.9 to 6.1.177, 6.6.x, 6.12.x, 6.13.x
Timeline
- 2026-05-14: other: Initial patch submitted by developer
- 2026-07-19: advisory: CVE-2026-53384 published
References
- https://git.kernel.org/stable/c/07ffe414a708ae60551401cec5d727ed156b8caf
- https://git.kernel.org/stable/c/10fc708b4de7f86002d2d735a2dbf3b5b7f65692
- https://git.kernel.org/stable/c/3d205fe80f2181f0109150ad1fa06ee5bc046935
- https://git.kernel.org/stable/c/511d2b92f8d20de04acafab676150d26fb5c67f4
- https://git.kernel.org/stable/c/778b9dda4b24005a27bcd9c35c110bf8d7f259ca
- https://git.kernel.org/stable/c/ccdf4510a3873b14e5e348cdb038717996f09fda
- https://git.kernel.org/stable/c/d72650a4f334581b23a1892b888a4cb1be142f76