« Volver al listado

CVE-2026-63876

Estado: Pendiente de análisisSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

serial: zs: Convert to use a platform device

Prevent a crash from happening as the first serial port is initialised:

(report at the offending commit) -- where a pointer is dereferenced that has been derived from a null pointer to the port's parent device.

Since no device is available with legacy probing and it's not anymore a preferable way to discover devices anyway, switch the driver to using a platform device and use it as the port's parent device. Update resource handling accordingly and only request the actual span of addresses used within the slot, which will have had its resource already requested by generic platform device code.

Leer descripción completaMostrar menos

Use platform_driver_probe() not just because SCC devices are fixed with solder on board and not straightforward to remove, but foremost because the associated TTY's major device number is the same as used by the dz driver and the first driver to claim it will prevent the other one from using it. Either one DZ device or some SCC devices will be present in a given system but never both at a time, and therefore we want the major device number to be claimed by the first driver to actually successfully bind to its device and platform_driver_probe() is a way to fulfil that.

An unfortunate consequence of the switch to a platform device is we now hand the console over from the bootconsole much later in the bootstrap. The firmware console handler appears good enough though to work so late and in particular with interrupts enabled.

Since there is one way only remaining to reach zs_reset() now, remove the port initialisation marker as no longer needed and go through the channel reset unconditionally.

Detalles técnicos trazas, registros y código del informe original
  Console: switching to mono frame buffer device 160x64
  fb0: PMAG-AA frame buffer device at tc0
  DECstation Z85C30 serial driver version 0.10
  CPU 0 Unable to handle kernel paging request at virtual address 0000002c, epc == 803ab00c, ra == 803aafe0
  Oops[#1]:
  CPU: 0 PID: 1 Comm: swapper Not tainted 6.4.0-rc3-00031-g84a9582fd203-dirty #57
  $ 0   : 00000000 10012c00 803aaeb0 00000000
  $ 4   : 80e12f60 80e12f50 80e12f58 81000030
  $ 8   : 00000000 805ff37c 00000000 33433538
  $12   : 65732030 00000006 80c2915d 6c616972
  $16   : 80e12f00 807b7630 00000000 00000000
  $20   : 00000004 00000348 000001a0 807623b8
  $24   : 00000018 00000000
  $28   : 80c24000 80c25d60 8078b148 803aafe0
  Hi    : 00000000
  Lo    : 00000000
  epc   : 803ab00c serial_base_ctrl_add+0x78/0xf4
  ra    : 803aafe0 serial_base_ctrl_add+0x4c/0xf4
  Status: 10012c03	KERNEL EXL IE
  Cause : 00000008 (ExcCode 02)
  BadVA : 0000002c
  PrId  : 00000440 (R4400SC)
  Modules linked in:
  Process swapper (pid: 1, threadinfo=(ptrval), task=(ptrval), tls=00000000)
  Stack : 80760000 00000cc0 00400044 00400040 803aa02c 80d61ab8 00000000 807b7630
          80760000 807623b8 807b7628 803aa644 80386998 00000000 80e17780 80220f68
          80e17780 80d61ab8 80c17d80 80e17780 80e17780 8063c798 80e17780 80383fa0
          00000010 80e17780 00000000 80386998 807a0000 00000000 00400040 8038f848
          807623b8 80d61ab8 00000004 80e17780 00000000 803a68e4 80c25e2c 803bb884
          ...
  Call Trace:
  [<803ab00c>] serial_base_ctrl_add+0x78/0xf4
  [<803aa644>] serial_core_register_port+0x174/0x69c
  [<8077e9ac>] zs_init+0xc8/0xfc
  [<800404d4>] do_one_initcall+0x40/0x2ac
  [<8076cecc>] kernel_init_freeable+0x1e4/0x270
  [<80605bec>] kernel_init+0x20/0x108
  [<800431e8>] ret_from_kernel_thread+0x14/0x1c

  Code: 2442aeb0  ae120024  ae0200d0 <8c67002c> 50e00001  8c670000  3c06806e  3c05806e  afb30010

  ---[ end trace 0000000000000000 ]---

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-63876",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "84a9582fd203063cd4d301204971ff2cd8327f1a",
              "lessThan": "bb2040484f90f91b717060e1a66026cc4287bcf0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "84a9582fd203063cd4d301204971ff2cd8327f1a",
              "lessThan": "6a83d5e24a84e746425cd93539130e5f7381ef47",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "84a9582fd203063cd4d301204971ff2cd8327f1a",
              "lessThan": "237dc8c08de3cb293b6607aaee8b13b3a671e267",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "84a9582fd203063cd4d301204971ff2cd8327f1a",
              "lessThan": "4dc9f1517503c883d5ce25b7ab29d177d05edc6a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "84a9582fd203063cd4d301204971ff2cd8327f1a",
              "lessThan": "7cac59d08a73cb866ec51a483a6f3fe0f531947c",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "arch/mips/dec/platform.c",
            "drivers/tty/serial/zs.c",
            "drivers/tty/serial/zs.h"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.5"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.5",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.143",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.93",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.35",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.0.12",
              "versionType": "semver",
              "lessThanOrEqual": "7.0.*"
            },
            {
              "status": "unaffected",
              "version": "7.1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "arch/mips/dec/platform.c",
            "drivers/tty/serial/zs.c",
            "drivers/tty/serial/zs.h"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-07-19T16:17:04.500",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/237dc8c08de3cb293b6607aaee8b13b3a671e267",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4dc9f1517503c883d5ce25b7ab29d177d05edc6a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6a83d5e24a84e746425cd93539130e5f7381ef47",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7cac59d08a73cb866ec51a483a6f3fe0f531947c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bb2040484f90f91b717060e1a66026cc4287bcf0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nserial: zs: Convert to use a platform device\n\nPrevent a crash from happening as the first serial port is initialised:\n\n  Console: switching to mono frame buffer device 160x64\n  fb0: PMAG-AA frame buffer device at tc0\n  DECstation Z85C30 serial driver version 0.10\n  CPU 0 Unable to handle kernel paging request at virtual address 0000002c, epc == 803ab00c, ra == 803aafe0\n  Oops[#1]:\n  CPU: 0 PID: 1 Comm: swapper Not tainted 6.4.0-rc3-00031-g84a9582fd203-dirty #57\n  $ 0   : 00000000 10012c00 803aaeb0 00000000\n  $ 4   : 80e12f60 80e12f50 80e12f58 81000030\n  $ 8   : 00000000 805ff37c 00000000 33433538\n  $12   : 65732030 00000006 80c2915d 6c616972\n  $16   : 80e12f00 807b7630 00000000 00000000\n  $20   : 00000004 00000348 000001a0 807623b8\n  $24   : 00000018 00000000\n  $28   : 80c24000 80c25d60 8078b148 803aafe0\n  Hi    : 00000000\n  Lo    : 00000000\n  epc   : 803ab00c serial_base_ctrl_add+0x78/0xf4\n  ra    : 803aafe0 serial_base_ctrl_add+0x4c/0xf4\n  Status: 10012c03\tKERNEL EXL IE\n  Cause : 00000008 (ExcCode 02)\n  BadVA : 0000002c\n  PrId  : 00000440 (R4400SC)\n  Modules linked in:\n  Process swapper (pid: 1, threadinfo=(ptrval), task=(ptrval), tls=00000000)\n  Stack : 80760000 00000cc0 00400044 00400040 803aa02c 80d61ab8 00000000 807b7630\n          80760000 807623b8 807b7628 803aa644 80386998 00000000 80e17780 80220f68\n          80e17780 80d61ab8 80c17d80 80e17780 80e17780 8063c798 80e17780 80383fa0\n          00000010 80e17780 00000000 80386998 807a0000 00000000 00400040 8038f848\n          807623b8 80d61ab8 00000004 80e17780 00000000 803a68e4 80c25e2c 803bb884\n          ...\n  Call Trace:\n  [<803ab00c>] serial_base_ctrl_add+0x78/0xf4\n  [<803aa644>] serial_core_register_port+0x174/0x69c\n  [<8077e9ac>] zs_init+0xc8/0xfc\n  [<800404d4>] do_one_initcall+0x40/0x2ac\n  [<8076cecc>] kernel_init_freeable+0x1e4/0x270\n  [<80605bec>] kernel_init+0x20/0x108\n  [<800431e8>] ret_from_kernel_thread+0x14/0x1c\n\n  Code: 2442aeb0  ae120024  ae0200d0 <8c67002c> 50e00001  8c670000  3c06806e  3c05806e  afb30010\n\n  ---[ end trace 0000000000000000 ]---\n\n(report at the offending commit) -- where a pointer is dereferenced that\nhas been derived from a null pointer to the port's parent device.\n\nSince no device is available with legacy probing and it's not anymore a\npreferable way to discover devices anyway, switch the driver to using a\nplatform device and use it as the port's parent device.  Update resource\nhandling accordingly and only request the actual span of addresses used\nwithin the slot, which will have had its resource already requested by\ngeneric platform device code.\n\nUse platform_driver_probe() not just because SCC devices are fixed with\nsolder on board and not straightforward to remove, but foremost because\nthe associated TTY's major device number is the same as used by the dz\ndriver and the first driver to claim it will prevent the other one from\nusing it.  Either one DZ device or some SCC devices will be present in a\ngiven system but never both at a time, and therefore we want the major\ndevice number to be claimed by the first driver to actually successfully\nbind to its device and platform_driver_probe() is a way to fulfil that.\n\nAn unfortunate consequence of the switch to a platform device is we now\nhand the console over from the bootconsole much later in the bootstrap.\nThe firmware console handler appears good enough though to work so late\nand in particular with interrupts enabled.\n\nSince there is one way only remaining to reach zs_reset() now, remove\nthe port initialisation marker as no longer needed and go through the\nchannel reset unconditionally."
    }
  ],
  "lastModified": "2026-07-27T17:44:23.777",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}