Executive brief
A memory management bug in the Linux kernel's serial device driver initialization can cause a system crash or unauthorized memory access. When the serial core tries to register a console port, failed memory allocations leave stale references that lead to null pointer dereferences or use-after-free conditions, potentially allowing attackers to crash the kernel or read sensitive memory.
Technical details
The vulnerability exists in serial_core_add_one_port() in drivers/tty/serial/serial_core.c. The function allocates memory for port attributes (uport->tty_groups and uport->name) after registering the console via uart_configure_port(). If these allocations fail, the console remains registered while the port structures are freed, leaving dangling pointers. This results in either NULL dereference crashes (PL011 console) or use-after-free conditions (i.MX console), as demonstrated by Failslab testing. The fix reorders allocations to occur before console registration and port linking, ensuring all memory is available before any irreversible state changes. Attack vector is local; requires triggering console registration with memory pressure or failslab instrumentation.
Affected products
- Linux Linux kernel multiple versions through 6.9 and earlier
Timeline
- 2026-09-17: disclosed
- 2026-08-03: patched: Patch commit 1a0e4fbce5d9c1bc179a35a2fd9ed142664299e3 merged
- 2026-07-31: other: Vulnerability report and fix authored by Karl Mehltretter