CVE-2026-53384: serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails

Published Jul 19, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

serial: 8250dw: unregister 8250 port if clknotifierregister() fails

dw8250probe() registers the 8250 port via serial8250register8250port() and then, if the device has a clock, registers a clock notifier. If clknotifierregister() fails, probe returns the error but leaves the 8250 port registered. The matching serial8250unregisterport() lives in dw8250remove(), which is not called when probe fails, so the port slot stays occupied until the device is rebound or the system is rebooted. The devm-allocated driver data is freed while the port still references it (via the saved privatedata and serialin/serialout callbacks), so any access to that port slot before a rebind is a use-after-free hazard.

Unregister the port on the clknotifierregister() error path.

Affected Software

8 affected componentsFixes available
Linux Linux kernel
Linux Linux kernel>=5.19<6.1.177
Linux Linux kernel>=6.2<6.6.144
Linux Linux kernel>=6.7<6.12.95
Linux Linux kernel>=6.13<6.18.38
Linux Linux kernel>=6.19<7.0.14
Linux Linux kernel>=7.1<7.1.2
Microsoft azl3 kernel 6.6.143.1-1<6.6.150.1-1
6.6.150.1-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 6.6.150.1-1
  2. Compensating control

    If you cannot apply the kernel fix yet, mitigate the use-after-free hazard by avoiding port-slot reuse during failed dw8250 probe paths (e.g., ensure the device is not probed/rebound repeatedly until a system reboot), since the occupied 8250 port slot persists until device rebinding or reboot.

Event History

Jul 19, 2026
CVE Published
via MITRE·11:59 AM
Data Sourced
via MITRE·11:59 AM
DescriptionSeverity
Data Sourced
via NVD·12:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jul 20, 2026
Data Sourced
via Microsoft·08:05 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:05 AM
Affected Software
Updated
via Microsoft·08:05 AM
DescriptionSeverity

Frequently Asked Questions

1

What is the severity of CVE-2026-53384?

The severity of CVE-2026-53384 is critical, with a CVSS score of 9.8.

2

How do I fix CVE-2026-53384?

To fix CVE-2026-53384, update the Linux kernel to a version that includes the patch for this vulnerability.

3

What impact does CVE-2026-53384 have on systems?

CVE-2026-53384 can potentially allow for a use-after-free condition, compromising system stability and security.

4

Which software is affected by CVE-2026-53384?

CVE-2026-53384 affects the Linux kernel specifically in its implementation of the 8250_dw serial driver.

5

How can I verify if my system is vulnerable to CVE-2026-53384?

You can verify if your system is vulnerable to CVE-2026-53384 by checking the Linux kernel version against the patched versions released.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203