Improper control of a resource through its lifetime in Linux kernel - CVE-2026-74654

 

Improper control of a resource through its lifetime in Linux kernel - CVE-2026-74654

Published: August 24, 2026


Vulnerability identifier: #VU144890
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-74654
CWE-ID: CWE-664
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper state management in serial8250_rx_dma_flush() and serial8250_release_dma() when reopening a port after it is closed during an active RX DMA transfer. A local user can close and reopen the serial port to trigger a kernel Oops and cause a denial of service.

The issue occurs because stale RX state can remain set while the RX DMA channel is unavailable.


Affected software

Linux kernel
Debian Linux
linux (Debian package)

How to mitigate CVE-2026-74654

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.105-1

External References

Related Security Bulletins