CVE-2026-53384
A flaw in the Linux kernel’s 8250_dw serial driver can leave a port registered even when a clock notifier fails, causing a use‑after‑free that could let an attacker run arbitrary code. The kernel has fixed the issue by unregistering the port on error. Users should update to a kernel version that includes this patch.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel, specifically the 8250_dw serial driver used on devices that rely on the 8250 port and a clock notifier.
Real-world impact
An attacker could trigger the use‑after‑free to execute code with kernel privileges, potentially taking full control of the affected system.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability can be exploited remotely without authentication, and it compromises confidentiality, integrity, and availability, giving attackers full control.
What to do about it
- 01Upgrade the Linux kernel to a version that includes the fix for CVE-2026-53384.
NVD description
Timeline
- Jul 19, 2026 · 11d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 29, 2026 · 17h agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- git.kernel.org/stable/c/07ffe414a708ae6055…patch
- git.kernel.org/stable/c/10fc708b4de7f86002…patch
- git.kernel.org/stable/c/3d205fe80f2181f010…patch
- git.kernel.org/stable/c/511d2b92f8d20de04a…patch
- git.kernel.org/stable/c/778b9dda4b24005a27…patch
- git.kernel.org/stable/c/ccdf4510a3873b14e5…patch
- git.kernel.org/stable/c/d72650a4f334581b23…patch