Junglewise Threat Intelligence

CVE-2026-63876: Linux kernel NULL pointer dereference in zs serial driver

CVE-2026-63876 · Severity: info · CVSS 5.5 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's serial driver for certain older hardware (DECstation) could cause the system to crash during startup. This occurs when the system attempts to initialize the first serial port using an outdated method, leading to a 'kernel panic' or 'oops' that halts operations. While this primarily affects older or specialized hardware configurations, it results in a complete loss of system availability.

Technical details

A vulnerability exists in the Linux kernel's 'zs' serial driver (drivers/tty/serial/zs.c) due to a NULL pointer dereference during port initialization. When using legacy probing, the driver attempts to derive a pointer from a NULL parent device reference in 'serial_base_ctrl_add', leading to a kernel oops. The fix involves converting the driver to use the platform device model, ensuring a valid parent device is associated with the port before registration. This issue was introduced by changes in serial core power management (runtime PM) that expected valid device parents for all registered ports.

Affected products

  • Linux Linux kernel 6.4.0-rc3 and earlier versions using legacy probing for zs serial driver

Timeline

  • 2026-05-06: patched: Initial patch authored by Maciej W. Rozycki
  • 2026-07-19: disclosed: CVE published to the NVD dataset

References

Related threats