CVE-2026-80737
In the Linux kernel, the following vulnerability has been resolved: serial: amba-pl011: synchronize DMA teardown dmaengine_terminate_all() does not wait for a running callback, so the TX callback can still touch the TX buffer after it is freed.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.16%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: serial: amba-pl011: synchronize DMA teardown dmaengine_terminate_all() does not wait for a running callback, so the TX callback can still touch the TX buffer after it is freed. The RX poll timer reads the RX buffers without the port lock. Switch to dmaengine_terminate_sync() and delete the RX timer before freeing the buffers.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.16% probability · 6th percentile
- CISA KEV
- Not listed
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/440915499231e9db1c361aa45bb702e8fd3b4a32
- https://git.kernel.org/stable/c/44bd0ecc3444882d08ecfbc2b2418d2f463d3186
- https://git.kernel.org/stable/c/5974cb66681eac367107b05924744d7e3b49d41c
- https://git.kernel.org/stable/c/9f6989e477f03a4721d34bb4b09b17accd40283e
- https://git.kernel.org/stable/c/a38fae9d212e2d3ed5e9ec0ef773f8c0a27fb76e
- https://git.kernel.org/stable/c/c8c8e895f65fbf71ea6224e27cf8dab91b776e0d
- https://git.kernel.org/stable/c/f70c9d4fba46463a5b1c7b3ee9ee3b40c90dac03
- https://git.kernel.org/stable/c/fdfb46c387241b4eddd36d746793764413285913
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.