{"id":"CVE-2026-90336","published":"2026-09-17T17:17:32.180","lastModified":"2026-09-17T17:17:32.180","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nserial: core: clear freed pointers on uart_register_driver() failure\n\nuart_register_driver() leaves drv->state pointing to freed memory when\ntty_alloc_driver() fails. If tty_register_driver() fails, drv->tty_driver\nalso retains a pointer after its reference is dropped.\n\nDrivers that use drv->state as an \"already registered\" flag can then skip\nregistration on the next probe and pass the freed state to\nuart_add_one_port().\n\nThis issue was found with failslab on QEMU's raspi1ap board by\nfailing registration and binding the PL011 port again.\n\nClear both pointers on their failure paths, as uart_unregister_driver()\nalready does.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/06b376432974fe5f25f2843a8e8438c6a1cf3d50","tags":[]},{"url":"https://git.kernel.org/stable/c/61a2fb25551be0375bc16ef2a70c987dfca26183","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}