SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-89740

UNKNOWN · CVSS N/A EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of UART ports, specifically in the imx_uart driver, where a dangling pointer can be left in the imx_uart_ports[] array if the port addition fails or after removal. This flaw can lead to a situation where a sibling probe may register a shared console using a stale entry, potentially causing system instability or unauthorized access. Organizations utilizing Linux systems with the imx_uart driver should prioritize addressing this vulnerability to mitigate risks associated with UART port management.

CVE
CVE-2026-89740
Severity
UNKNOWN
CVSS
N/A
EPSS
0.20%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: serial: imx: serialize imx_uart_ports[] lifetime imx_uart_probe() publishes its devm-allocated port in imx_uart_ports[] before uart_add_one_port() because console setup uses the table. The entry is not cleared when adding the port fails or after removal, leaving a dangling pointer. A sibling probe can register the shared console through that stale entry. This was reproduced under KASAN on QEMU mcimx6ul-evk by unbinding a sibling UART, unbinding the console UART and rebinding the sibling. Keep the entry valid through uart_remove_one_port(), then clear it. Protect port addition and removal together with their table updates so sibling operations cannot interleave. Reject an occupied slot rather than clobbering an active port during a duplicate-line probe.