CVE-2026-53384: serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails
In the Linux kernel, the following vulnerability has been resolved:
serial: 8250dw: unregister 8250 port if clknotifierregister() fails
dw8250probe() registers the 8250 port via serial8250register8250port() and then, if the device has a clock, registers a clock notifier. If clknotifierregister() fails, probe returns the error but leaves the 8250 port registered. The matching serial8250unregisterport() lives in dw8250remove(), which is not called when probe fails, so the port slot stays occupied until the device is rebound or the system is rebooted. The devm-allocated driver data is freed while the port still references it (via the saved privatedata and serialin/serialout callbacks), so any access to that port slot before a rebind is a use-after-free hazard.
Unregister the port on the clknotifierregister() error path.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.150.1-1 - Compensating control
If you cannot apply the kernel fix yet, mitigate the use-after-free hazard by avoiding port-slot reuse during failed dw8250 probe paths (e.g., ensure the device is not probed/rebound repeatedly until a system reboot), since the occupied 8250 port slot persists until device rebinding or reboot.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53384?
The severity of CVE-2026-53384 is critical, with a CVSS score of 9.8.
How do I fix CVE-2026-53384?
To fix CVE-2026-53384, update the Linux kernel to a version that includes the patch for this vulnerability.
What impact does CVE-2026-53384 have on systems?
CVE-2026-53384 can potentially allow for a use-after-free condition, compromising system stability and security.
Which software is affected by CVE-2026-53384?
CVE-2026-53384 affects the Linux kernel specifically in its implementation of the 8250_dw serial driver.
How can I verify if my system is vulnerable to CVE-2026-53384?
You can verify if your system is vulnerable to CVE-2026-53384 by checking the Linux kernel version against the patched versions released.