๐Ÿ” CVE Alert

CVE-2026-90337

UNKNOWN 0.0

serial: core: do fallible allocations before the console can be registered

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: serial: core: do fallible allocations before the console can be registered serial_core_add_one_port() allocates uport->tty_groups after uart_configure_port(), which may register the console. If the allocation fails, the driver unwinds the port while its console remains registered. The earlier uport->name allocation has a related failure path that leaves state->uart_port linked to a port being freed. Failslab reproduced a NULL dereference in PL011 console output and a KASAN use-after-free in i.MX console output after failed binds. Allocate the name and tty_groups before linking the port and configuring it. Reserve space for the optional driver attribute group because config_port() may populate uport->attr_group during configuration.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
266dcff03eed0050b6af11aaf2a61ab837d7ba3f < c2aec15f78b2e6ccd9b94216a901248511355982 266dcff03eed0050b6af11aaf2a61ab837d7ba3f < 1a0e4fbce5d9c1bc179a35a2fd9ed142664299e3
Linux / Linux
3.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/c2aec15f78b2e6ccd9b94216a901248511355982 git.kernel.org: https://git.kernel.org/stable/c/1a0e4fbce5d9c1bc179a35a2fd9ed142664299e3