Use-after-free in Linux kernel - CVE-2026-53384

 

Use-after-free in Linux kernel - CVE-2026-53384

Published: July 21, 2026


Vulnerability identifier: #VU138878
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-53384
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service or execute arbitrary code.

The vulnerability exists due to a use-after-free in the 8250_dw serial driver when handling a failed clock notifier registration during device probe. A local user can trigger the error path and access the stale port slot to cause a denial of service or execute arbitrary code.

The issue occurs because the 8250 port remains registered after probe failure while its associated driver data has already been freed.


Affected software

Linux kernel

How to mitigate CVE-2026-53384

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins