Use-after-free in Linux kernel - CVE-2026-53384
Published: July 21, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service or execute arbitrary code.
The vulnerability exists due to a use-after-free in the 8250_dw serial driver when handling a failed clock notifier registration during device probe. A local user can trigger the error path and access the stale port slot to cause a denial of service or execute arbitrary code.
The issue occurs because the 8250 port remains registered after probe failure while its associated driver data has already been freed.
Affected software
How to mitigate CVE-2026-53384
External References
- https://git.kernel.org/stable/c/07ffe414a708ae60551401cec5d727ed156b8caf
- https://git.kernel.org/stable/c/10fc708b4de7f86002d2d735a2dbf3b5b7f65692
- https://git.kernel.org/stable/c/3d205fe80f2181f0109150ad1fa06ee5bc046935
- https://git.kernel.org/stable/c/511d2b92f8d20de04acafab676150d26fb5c67f4
- https://git.kernel.org/stable/c/778b9dda4b24005a27bcd9c35c110bf8d7f259ca
- https://git.kernel.org/stable/c/ccdf4510a3873b14e5e348cdb038717996f09fda
- https://git.kernel.org/stable/c/d72650a4f334581b23a1892b888a4cb1be142f76