From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 506BA592219 for ; Fri, 11 Sep 2026 20:06:55 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789157220; cv=none; b=GTc24QKPNScp9SRhDVfDOp86laUrZCILrR/5roq0HlHiEQ0hk02k/KyEIJmtkj+3w+4J4ANsPcC09CmZk5oMSlmfHPpl3CSyCuRfzA+dVHq1wY9zIYGN+LfXOQ54ow7YESm21ym5aCeYncLlu0Fd5II5q4xkfokNDGPjKqhGhuw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789157220; c=relaxed/simple; bh=rud36XpSHPLANP02I6ra1N5VszITuk9TiSD+dIw2u3Q=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=STF1hYWBDrz4dye/jiNwsSKblDV3s/4ynCPAL63hXhrTXlcwnPVARV/lih6PH4rYGV2Spk6D+LUEmpgW/vvjKkoz+N4WJXXvf85AyYqNIKKdL7lzjgLZT9WhsinML9IkbEAudXjzBukm26dJrKM+WN9DgC5ObdtndZyqghE9/p4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=LfI2j2XC; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="LfI2j2XC" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 5E7DF1F00898; Fri, 11 Sep 2026 20:06:53 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789157213; bh=r2b786TLtkVLJIxq9Sb+cyIb2VkzjszqIL2n1z18Afw=; h=From:To:Cc:Subject:Date:Reply-To; b=LfI2j2XCGZQ4j4bJHfJsp5ggOJ+FE6itY6jw0HwFeKuA7iq2fP4Zn1x7i8/iShUdT y/b1VzomPiMPihhgqUZ7RxHR7GT3Cc2ZiZMR+caDhu68FHxObgBLapFq3haTiYElCF +UQ08NXPQNE7EKuzAZHb2xtXvcqFpDSlBwtMjNCs= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89740: serial: imx: serialize imx_uart_ports[] lifetime Date: Fri, 11 Sep 2026 21:47:09 +0200 Message-ID: <2026091104-CVE-2026-89740-ee43@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2952; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=dK82EBilEDJPXZrk2yfLWgqE8r4vy5BJthUMRpRDaiA=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLInuUPdt5TrY/lz14O/je5zdqvjLVD+fWhC6PqbjE0 euyTuZFRywLgyATg6yYIsuXbTxH91ccUvQytD0NM4eVCWQIAxenAExEwZxhwWHXOW8TS5m7V7LE 5d/5LXfJ7dyeRoY5PHVPDJM/7Io7PVd98na+GbWK0fd+AQA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: serial: imx: serialize imx_uart_ports[] lifetime imx_uart_probe() publishes its devm-allocated port in imx_uart_ports[] before uart_add_one_port() because console setup uses the table. The entry is not cleared when adding the port fails or after removal, leaving a dangling pointer. A sibling probe can register the shared console through that stale entry. This was reproduced under KASAN on QEMU mcimx6ul-evk by unbinding a sibling UART, unbinding the console UART and rebinding the sibling. Keep the entry valid through uart_remove_one_port(), then clear it. Protect port addition and removal together with their table updates so sibling operations cannot interleave. Reject an occupied slot rather than clobbering an active port during a duplicate-line probe. The Linux kernel CVE team has assigned CVE-2026-89740 to this issue. Affected and fixed versions =========================== Issue introduced in 2.6.27 with commit dbff4e9ea2e83fda89143389bfb229cb29425a32 and fixed in 6.12.109 with commit 681696ae9e4a28bdf54893c807dfe4a6c08e30a5 Issue introduced in 2.6.27 with commit dbff4e9ea2e83fda89143389bfb229cb29425a32 and fixed in 6.18.50 with commit 28b932202fcdbeb2ef58d89ce4363f480433c234 Issue introduced in 2.6.27 with commit dbff4e9ea2e83fda89143389bfb229cb29425a32 and fixed in 7.2.4 with commit 7429dce56a73bc080a8c072edb167106f73a08ae Issue introduced in 2.6.27 with commit dbff4e9ea2e83fda89143389bfb229cb29425a32 and fixed in 7.3-rc1 with commit 8b0b29fdcb47907ae0296b8fe829e918e05e300f Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89740 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/tty/serial/imx.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/681696ae9e4a28bdf54893c807dfe4a6c08e30a5 https://git.kernel.org/stable/c/28b932202fcdbeb2ef58d89ce4363f480433c234 https://git.kernel.org/stable/c/7429dce56a73bc080a8c072edb167106f73a08ae https://git.kernel.org/stable/c/8b0b29fdcb47907ae0296b8fe829e918e05e300f