SB2026050614 - Improper control of a resource through its lifetime in Linux kernel serial 8250 driver



SB2026050614 - Improper control of a resource through its lifetime in Linux kernel serial 8250 driver

Published: May 6, 2026

Security Bulletin ID SB2026050614
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-43061)

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper state management in the 8250 serial DMA transmit handling when terminating a DMA transaction asynchronously. A local user can trigger cancellation of a transmit DMA transaction to cause a denial of service.

The issue can leave transmit DMA permanently stalled because the tx_running state is not cleared if the completion callback does not run.


Remediation

Install update from vendor's website.