Improper control of a resource through its lifetime in Linux kernel - CVE-2026-74654
Published: August 24, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper state management in serial8250_rx_dma_flush() and serial8250_release_dma() when reopening a port after it is closed during an active RX DMA transfer. A local user can close and reopen the serial port to trigger a kernel Oops and cause a denial of service.
The issue occurs because stale RX state can remain set while the RX DMA channel is unavailable.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74654
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/9f2444f4c0e4b06f61bae38da87c9c94c78efa86
- https://git.kernel.org/stable/c/ae05d9e50b6b9f246c110b3bdc03676145c2d0d4
- https://git.kernel.org/stable/c/bf4fb620e02962b2b52500a4b3d8420f351eb46a
- https://git.kernel.org/stable/c/d06cfb1add4a2d5b393e9e31f49ebbd168beea49
- https://git.kernel.org/stable/c/e10f06ee050a08930e2339b6fec7148fd0b2a8f6
- https://git.kernel.org/stable/c/e2fe6a0efecbef00e3ecc2db64dd5afa8c212b41
- https://git.kernel.org/stable/c/e7a5d792cf64a2096e18f1d573cc3d01cba15e92
- https://git.kernel.org/stable/c/e7e3cc6709caa49d1d6ce6c1f7cb305e38675cc9