Executive brief
The AMBA PL011 serial driver, used in Linux systems for RS485 serial communication, contains a use-after-free vulnerability in its timer handling. When the device is shut down or removed, high-resolution timers can fire after their parent data structure has been freed from memory, potentially causing a system crash or unexpected behavior. This affects systems using RS485 serial interfaces with this driver.
Technical details
The vulnerability is a use-after-free condition in the PL011 driver's RS485 implementation. The RS485 trigger hrtimers are embedded in a devm-managed port structure; when the device is freed, these timers can still fire because the IRQ handler is freed before the timers are cancelled. The fix reorders the shutdown sequence: cancel the hrtimers after freeing the IRQ (not before), add an explicit timer cancellation in the remove() path for the suspend-then-unbind scenario, and refactor the RS485 stop logic to avoid arming timers during shutdown. The IRQ handler can arm timers, so timers must be cancelled after free_irq() completes to prevent use-after-free. No authentication or user interaction is required; the vulnerability is triggered during normal device shutdown.
Affected products
- Linux Linux kernel multiple versions (see kernel stable tree branches linux-4.14.y through linux-6.x.y listed in references)
Timeline
- 2026-08-22: disclosed: Published to NVD
- 2026-08-03: patched: Patch committed by Greg Kroah-Hartman (commit 36672c8d7d14e9c43287528455d2c97b526ea6ad)