CVE-2026-12629: PL011 UART error interrupts never cleared, enabling an external-peer interrupt-storm denial of service
The ARM PL011 UART driver in drivers/serial/uartpl011.c fails to acknowledge receive error interrupts. On the PL011, the framing, parity, break, and overrun error interrupts (PL011IMSCERRORMASK) are cleared only by writing the interrupt-clear register UARTICR; reading the data register clears the RX interrupt and the per-byte RSR status but not the error interrupt status in MIS. The interrupt service routine pl011isr() acknowledged only the CTS modem-status interrupt and never wrote icr for the error bits, so an asserted error interrupt remains pending after the ISR returns.
When an application enables error-interrupt reporting via the public uartirqerrenable() API, an attacker who controls the serial peer can deterministically assert these error bits by injecting line errors on the RX line — a baud/stop-bit mismatch or mid-character break (framing/break error), a flipped parity bit (parity error), or FIFO flooding (overrun error). Because the error interrupt is never cleared, the interrupt line stays asserted and the CPU re-enters pl011isr() immediately and indefinitely, producing an interrupt-storm livelock from which the core makes no forward progress.
The impact is an availability-only denial of service (permanent hang), reachable from an external or removable UART peer. Exploitation is gated by configuration: the error interrupt is off by default and no in-tree subsystem enables it, so only applications that explicitly call uartirqerrenable() on a PL011-based, interrupt-driven port are affected. The fix makes pl011isr() acknowledge the pending error bits via uart->icr, breaking the loop, and additionally clears the latched RSR status in pl011errcheck().
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Avoid enabling PL011 receive error interrupts via the uart_irq_err_enable() API on PL011-based interrupt-driven UART ports unless needed, since affected error interrupts are latched and can cause an interrupt-storm livelock.
PL011 UART (drivers/serial/uart_pl011.c) uart_irq_err_enable() / PL011 error interrupt enablement = disable error-interrupt reporting unless explicitly required - Configuration
In pl011_isr(), acknowledge the pending receive error interrupts by writing to the interrupt-clear register (uart->icr / UARTICR) for the PL011_IMSC_ERROR_MASK error bits, so the asserted error interrupt is cleared and the core does not re-enter pl011_isr() indefinitely.
PL011 UART Interrupt clearing mechanism for error bits (UARTICR via uart->icr) = write UARTICR to acknowledge pending error bits via pl011_isr() - Configuration
In pl011_err_check(), additionally clear the latched RSR status so the latched error state does not remain set after interrupt handling.
PL011 UART pl011_err_check() latched RSR status clearing = clear latched RSR status
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12629?
CVE-2026-12629 has a medium severity score of 4.6.
How do I fix CVE-2026-12629?
To fix CVE-2026-12629, ensure that the UART driver acknowledges and clears receive error interrupts properly.
What impact does CVE-2026-12629 have?
CVE-2026-12629 can lead to an external-peer interrupt-storm denial of service.
Which software is affected by CVE-2026-12629?
CVE-2026-12629 affects the Arm PL011 UART driver in the Linux kernel.
What type of vulnerability is CVE-2026-12629?
CVE-2026-12629 is a denial of service vulnerability due to unacknowledged UART error interrupts.