Junglewise Threat Intelligence

CVE-2026-74652: Linux kernel AMBA PL011 serial driver use-after-free in RS485 hrtimers

CVE-2026-74652 · Severity: high · CVSS 7.8 · Published 2026-08-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The AMBA PL011 serial driver, used in Linux systems for RS485 serial communication, contains a use-after-free vulnerability in its timer handling. When the device is shut down or removed, high-resolution timers can fire after their parent data structure has been freed from memory, potentially causing a system crash or unexpected behavior. This affects systems using RS485 serial interfaces with this driver.

Technical details

The vulnerability is a use-after-free condition in the PL011 driver's RS485 implementation. The RS485 trigger hrtimers are embedded in a devm-managed port structure; when the device is freed, these timers can still fire because the IRQ handler is freed before the timers are cancelled. The fix reorders the shutdown sequence: cancel the hrtimers after freeing the IRQ (not before), add an explicit timer cancellation in the remove() path for the suspend-then-unbind scenario, and refactor the RS485 stop logic to avoid arming timers during shutdown. The IRQ handler can arm timers, so timers must be cancelled after free_irq() completes to prevent use-after-free. No authentication or user interaction is required; the vulnerability is triggered during normal device shutdown.

Affected products

  • Linux Linux kernel multiple versions (see kernel stable tree branches linux-4.14.y through linux-6.x.y listed in references)

Timeline

  • 2026-08-22: disclosed: Published to NVD
  • 2026-08-03: patched: Patch committed by Greg Kroah-Hartman (commit 36672c8d7d14e9c43287528455d2c97b526ea6ad)

References

Related threats