#VU124898 Improper Initialization in Linux kernel - CVE-2026-23472
Published: April 6, 2026
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper initialization handling in handle_tx() when processing PORT_UNKNOWN serial ports. A local user can use a PORT_UNKNOWN serial port to trigger an infinite loop and cause a denial of service.
This issue occurs because write-room reporting can indicate available space while write operations return zero when the transmit buffer is NULL, which can lead to a system hang.