Junglewise Threat Intelligence

CVE-2026-80737: Linux kernel amba-pl011 use-after-free in DMA teardown

CVE-2026-80737 · Severity: high · CVSS 7.8 · Published 2026-09-03

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The ARM PL011 serial port driver in the Linux kernel contains a race condition during shutdown where DMA callbacks and timers can access memory buffers after they have been freed. An attacker with local access to a system using this driver could trigger a kernel crash or potentially execute code by causing the use-after-free condition, leading to system unavailability or privilege escalation.

Technical details

The vulnerability is a use-after-free race condition in the amba-pl011 serial driver's DMA shutdown routine. The root cause is that dmaengine_terminate_all() does not wait for in-flight DMA callbacks to complete before the function returns, allowing the TX callback to still access the TX buffer after it has been freed. Additionally, the RX poll timer reads RX buffers without holding the port lock, creating a concurrent access issue. The fix replaces dmaengine_terminate_all() with dmaengine_terminate_sync() and ensures the RX timer is deleted synchronously before buffer deallocation. This vulnerability affects any system running affected kernel versions where the PL011 serial driver with DMA support is enabled, typically on ARM-based platforms. A local attacker can exploit this via careful timing of serial port closure or driver module unload.

Affected products

  • Linux Linux kernel Versions prior to fix; affects multiple stable branches from 2.6.11 onwards

Timeline

  • 2026-09-03: disclosed: CVE-2026-80737 published
  • 2026-07-31: patched: Fix authored by Fan Wu
  • 2026-08-03: patched: Fix merged into stable kernel
  • 2026-08-21: advisory: Backported to stable kernels

References

Related threats