CVE-2026-74654
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/08/2026
Last modified:
22/08/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
serial: 8250_dma: Clear stale RX state on shutdown<br />
<br />
serial8250_release_dma() terminates RX DMA and releases the channel, but<br />
leaves rx_running set. If the port is closed while an RX transfer is<br />
active, the stale state remains while rxchan is NULL until the channel is<br />
requested again on the next open.<br />
<br />
The DesignWare BUSY workaround added by commit a7b9ce39fbe4<br />
("serial: 8250_dw: Ensure BUSY is deasserted") calls<br />
serial8250_rx_dma_flush() from the LCR write path during startup. This<br />
happens before serial8250_request_dma() obtains a new RX channel. On<br />
reopen, the stale rx_running state therefore makes the flush path pass a<br />
NULL channel to dmaengine_pause(), causing a kernel Oops.<br />
<br />
Clear rx_running after terminating RX DMA, matching the TX cleanup. Also<br />
make the flush helper return if the DMA object or RX channel is not<br />
available so startup and teardown paths cannot pass a NULL channel to the<br />
DMAengine API.
Impact
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/9f2444f4c0e4b06f61bae38da87c9c94c78efa86
- https://git.kernel.org/stable/c/ae05d9e50b6b9f246c110b3bdc03676145c2d0d4
- https://git.kernel.org/stable/c/bf4fb620e02962b2b52500a4b3d8420f351eb46a
- https://git.kernel.org/stable/c/d06cfb1add4a2d5b393e9e31f49ebbd168beea49
- https://git.kernel.org/stable/c/e10f06ee050a08930e2339b6fec7148fd0b2a8f6
- https://git.kernel.org/stable/c/e2fe6a0efecbef00e3ecc2db64dd5afa8c212b41
- https://git.kernel.org/stable/c/e7a5d792cf64a2096e18f1d573cc3d01cba15e92
- https://git.kernel.org/stable/c/e7e3cc6709caa49d1d6ce6c1f7cb305e38675cc9


