Junglewise Threat Intelligence

CVE-2026-74653: Linux kernel 8250_of UART interrupt livelock on LPC32xx

CVE-2026-74653 · Severity: info · Published 2026-08-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's serial driver for NXP LPC32xx UART controllers contains a bug where a stuck receive timeout interrupt can cause the CPU to livelock, rendering the system unresponsive when serial ports are repeatedly opened. This affects systems using LPC32xx processors with active UART communications, potentially causing denial of service.

Technical details

The vulnerability is a logic error in the 8250_of serial driver's interrupt handler for PORT_LPC3220 (NXP LPC32xx UART). When a character-timeout interrupt fires while the RX FIFO is empty, the handler never clears the condition because it only reads the receive buffer when the data-ready flag is set—creating an interrupt storm. The root cause is that character timeouts require a throwaway RHR read to clear, regardless of FIFO state. The fix adds a hardware-specific interrupt handler that detects this condition (IIR=0x0c with LSR.DR clear) and performs one dummy RHR read before proceeding. This is a known class of bug in other 8250 variants (dw8250, bcm7271, omap). The vulnerability requires the system to use an LPC32xx UART and for userspace to repeatedly open/close the serial port, making it practical to trigger on single-core ARM926 systems.

Affected products

  • Linux Linux kernel affected versions not specified in advisory

Timeline

  • 2026-08-22: disclosed

Related threats