« Volver al listado

CVE-2026-97480

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

tty: serial: 8250: protect against NULL uart->port.dev in register

serial8250_register_8250_port() conditionally copies uart->port.dev from up->port.dev only when up->port.dev is non-NULL:

So if both the existing uart slot and up have a NULL ->dev, uart->port.dev remains NULL. The very next ACPI companion check then dereferences it unconditionally:

has_acpi_companion() reads dev->fwnode without a NULL guard (include/linux/acpi.h), so this NULL-derefs the kernel for the remaining no-dev case rather than just skipping the mctrl_gpio_init() initialisation as intended.

Leer descripción completaMostrar menos

smatch flags the inconsistency:

Guard the call with a NULL check so register continues to work for callers that legitimately have no parent device (legacy non-OF/non-ACPI registrations).

No functional change for callers that pass a non-NULL ->dev.

Detalles técnicos trazas, registros y código del informe original
	if (up->port.dev) {
		uart->port.dev = up->port.dev;
		...
	}

	if (!has_acpi_companion(uart->port.dev)) {

  drivers/tty/serial/8250/8250_core.c:767
  serial8250_register_8250_port() error: 'uart->port.dev' could be
  null (see line 719)

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97480",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4a96895f74c9633b51427fd080ab70fa62b65bc4",
              "lessThan": "5cbab666721d974bfe033a12045d808936deaefd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4a96895f74c9633b51427fd080ab70fa62b65bc4",
              "lessThan": "941c9f84c9b6310f7aaa1c8c785dcc634ee33050",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/tty/serial/8250/8250_core.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.3"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.3",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/tty/serial/8250/8250_core.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-24T17:17:25.467",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/5cbab666721d974bfe033a12045d808936deaefd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/941c9f84c9b6310f7aaa1c8c785dcc634ee33050",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntty: serial: 8250: protect against NULL uart->port.dev in register\n\nserial8250_register_8250_port() conditionally copies uart->port.dev\nfrom up->port.dev only when up->port.dev is non-NULL:\n\n\tif (up->port.dev) {\n\t\tuart->port.dev = up->port.dev;\n\t\t...\n\t}\n\nSo if both the existing uart slot and up have a NULL ->dev,\nuart->port.dev remains NULL. The very next ACPI companion check\nthen dereferences it unconditionally:\n\n\tif (!has_acpi_companion(uart->port.dev)) {\n\nhas_acpi_companion() reads dev->fwnode without a NULL guard\n(include/linux/acpi.h), so this NULL-derefs the kernel for the\nremaining no-dev case rather than just skipping the\nmctrl_gpio_init() initialisation as intended.\n\nsmatch flags the inconsistency:\n\n  drivers/tty/serial/8250/8250_core.c:767\n  serial8250_register_8250_port() error: 'uart->port.dev' could be\n  null (see line 719)\n\nGuard the call with a NULL check so register continues to work\nfor callers that legitimately have no parent device (legacy\nnon-OF/non-ACPI registrations).\n\nNo functional change for callers that pass a non-NULL ->dev."
    }
  ],
  "lastModified": "2026-09-28T06:16:34.003",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}