CVE-2026-23472
published 2026-04-03CVE-2026-23472: In the Linux kernel, the following vulnerability has been resolved: serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN uart_write_room() and…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.3th percentile
In the Linux kernel, the following vulnerability has been resolved:
serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN
uart_write_room() and uart_write() behave inconsistently when
xmit_buf is NULL (which happens for PORT_UNKNOWN ports that were
never properly initialized):
- uart_write_room() returns kfifo_avail() which can be > 0
- uart_write() checks xmit_buf and returns 0 if NULL
This inconsistency causes an infinite loop in drivers that rely on
tty_write_room() to determine if they can write:
while (tty_write_room(tty) > 0) {
written = tty->ops->write(...);
// written is always 0, loop never exits
}
For example, caif_serial's handle_tx() enters an infinite loop when
used with PORT_UNKNOWN serial ports, causing system hangs.
Fix by making uart_write_room() also check xmit_buf and return 0 if
it's NULL, consistent with uart_write().
Reproducer: https://gist.github.com/mrpre/d9a694cc0e19828ee3bc3b37983fde13
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.19.10-1 (forky) | linux 6.19.10-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < efe85a557186b7fe915572ae93a8f3f78bfd9a22 | efe85a557186b7fe915572ae93a8f3f78bfd9a22 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < bc70f2b36cf474d5cc8ecbcaf57f3e326fdec67c | bc70f2b36cf474d5cc8ecbcaf57f3e326fdec67c |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 455ce986fa356ff43a43c0d363ba95fa152f21d5 | 455ce986fa356ff43a43c0d363ba95fa152f21d5 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.19.10-1 | 6.19.10-1 |
| linux | linux_kernel | >= 2.6.12.1 < 6.18.20 | 6.18.20 |
| linux | linux_kernel | >= 6.19 < 6.19.10 | 6.19.10 |
| msrc | azl3_kernel_6.6.130.1-3_on_azure_linux_3.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN
vendor_redhat·2026-04-03·CVSS 5.5
CVE-2026-23472 [MEDIUM] CWE-474 kernel: serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN
kernel: serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN
In the Linux kernel, the following vulnerability has been resolved:
serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN
uart_write_room() and uart_write() behave inconsistently when
xmit_buf is NULL (which happens for PORT_UNKNOWN ports that were
never properly initialized):
- uart_write_room() returns kfifo_avail() which can be > 0
- uart_write() checks xmit_buf and returns 0 if NULL
This inconsistency causes an infinite loop in drivers that rely on
tty_write_room() to determine if they can write:
while (tty_write_room(tty) > 0) {
written = tty->ops->write(...);
// written is always 0, loop never exits
}
For example, caif_serial's handle_tx() enters an infinite loop when
used with PORT_UNKNOWN serial port
Microsoft
serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN
vendor_msrc·2026-04-02·CVSS 5.5
CVE-2026-23472 [MEDIUM] serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN
serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN
Mariner: Mariner
Linux: Linux
Customer Action Required: Yes
Debian
CVE-2026-23472: linux - In the Linux kernel, the following vulnerability has been resolved: serial: cor...
vendor_debian·2026
CVE-2026-23472 CVE-2026-23472: linux - In the Linux kernel, the following vulnerability has been resolved: serial: cor...
In the Linux kernel, the following vulnerability has been resolved: serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN uart_write_room() and uart_write() behave inconsistently when xmit_buf is NULL (which happens for PORT_UNKNOWN ports that were never properly initialized): - uart_write_room() returns kfifo_avail() which can be > 0 - uart_write() checks xmit_buf and returns 0 if NULL This inconsistency causes an infinite loop in drivers that rely on tty_write_room() to determine if they can write: while (tty_write_room(tty) > 0) { written = tty->ops->write(...); // written is always 0, loop never exits } For example, caif_serial's handle_tx() enters an infinite loop when used with PORT_UNKNOWN serial ports, causing system hangs. Fix by making uart_write_room() also check xmit_
VulDB
Linux Kernel up to 6.18.19/6.19.9/7.0-rc4 serial handle_tx infinite loop (Nessus ID 317729)
vuldb·2026-07-21·CVSS 5.5
CVE-2026-23472 [MEDIUM] Linux Kernel up to 6.18.19/6.19.9/7.0-rc4 serial handle_tx infinite loop (Nessus ID 317729)
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.18.19/6.19.9/7.0-rc4. This issue affects the function handle_tx of the component serial. The manipulation leads to infinite loop.
This vulnerability is traded as CVE-2026-23472. Access to the local network is required for this attack to succeed. There is no exploit available.
It is advisable to upgrade the affected component.
OSV
CVE-2026-23472: In the Linux kernel, the following vulnerability has been resolved: serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN uart_write_room()
osv·2026-04-03
CVE-2026-23472 CVE-2026-23472: In the Linux kernel, the following vulnerability has been resolved: serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN uart_write_room()
In the Linux kernel, the following vulnerability has been resolved: serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN uart_write_room() and uart_write() behave inconsistently when xmit_buf is NULL (which happens for PORT_UNKNOWN ports that were never properly initialized): - uart_write_room() returns kfifo_avail() which can be > 0 - uart_write() checks xmit_buf and returns 0 if NULL This inconsistency causes an infinite loop in drivers that rely on tty_write_room() to determine if they can write: while (tty_write_room(tty) > 0) { written = tty->ops->write(...); // written is always 0, loop never exits } For example, caif_serial's handle_tx() enters an infinite loop when used with PORT_UNKNOWN serial ports, causing system hangs. Fix by making uart_write_room() also check xmit_
GHSA
GHSA-xx77-8cp4-rx22: In the Linux kernel, the following vulnerability has been resolved:
serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN
uart_write_room(
ghsa_unreviewed·2026-04-03
CVE-2026-23472 GHSA-xx77-8cp4-rx22: In the Linux kernel, the following vulnerability has been resolved:
serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN
uart_write_room(
In the Linux kernel, the following vulnerability has been resolved:
serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN
uart_write_room() and uart_write() behave inconsistently when
xmit_buf is NULL (which happens for PORT_UNKNOWN ports that were
never properly initialized):
- uart_write_room() returns kfifo_avail() which can be > 0
- uart_write() checks xmit_buf and returns 0 if NULL
This inconsistency causes an infinite loop in drivers that rely on
tty_write_room() to determine if they can write:
while (tty_write_room(tty) > 0) {
written = tty->ops->write(...);
// written is always 0, loop never exits
}
For example, caif_serial's handle_tx() enters an infinite loop when
used with PORT_UNKNOWN serial ports, causing system hangs.
Fix by making uart_write_room() also chec
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-23472 kernel: serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN
bugzilla·2026-04-03·CVSS 5.5
CVE-2026-23472 [MEDIUM] CVE-2026-23472 kernel: serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN
CVE-2026-23472 kernel: serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN
In the Linux kernel, the following vulnerability has been resolved:
serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN
uart_write_room() and uart_write() behave inconsistently when
xmit_buf is NULL (which happens for PORT_UNKNOWN ports that were
never properly initialized):
- uart_write_room() returns kfifo_avail() which can be > 0
- uart_write() checks xmit_buf and returns 0 if NULL
This inconsistency causes an infinite loop in drivers that rely on
tty_write_room() to determine if they can write:
while (tty_write_room(tty) > 0) {
written = tty->ops->write(...);
// written is always 0, loop never exits
}
For example, caif_serial's handle_tx() enters an infinite loop when
used with POR
Wiz
CVE-2026-23472 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2026-23472 CVE-2026-23472 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23472 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN
uart_write_room() and uart_write() behave inconsistently when
xmit_buf is NULL (which happens for PORT_UNKNOWN ports that were
never properly initialized):
uart_write_room() returns kfifo_avail() which can be > 0
uart_write() checks xmit_buf and returns 0 if NULL
This inconsistency causes an infinite loop in drivers that rely on
tty_write_room() to determine if they can write:
while (tty_write_room(tty) > 0) {
written = tty->ops->write(...);
// written is always 0, loop never exits
}
For example, caif_serial's handle_tx() enters an infinite loop when
used with PORT_UNKNOWN serial p
2026-04-03
Published