PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-97480 Linux CVE debrief

A vulnerability in the Linux kernel's serial 8250 driver can cause a NULL pointer dereference when registering a serial port without a parent device. This issue arises from the driver's failure to properly handle cases where both the existing uart slot and the up structure have a NULL ->dev field. As a result, the has_acpi_companion() function may dereference a NULL pointer, leading to a kernel crash.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-24
Original CVE updated
2026-09-28
Advisory published
2026-09-24
Advisory updated
2026-09-28

Who should care

Linux kernel developers and maintainers, Linux distribution vendors, and users of Linux-based systems that utilize the serial 8250 driver. These stakeholders should assess their exposure to this vulnerability and apply patches to mitigate the risk. Additionally, Linux-based system administrators and security teams should be aware of the potential impact on their systems and take appropriate measures to ensure their system's stability and security.

Why it matters

This vulnerability in the Linux kernel's serial 8250 driver can cause system instability or crashes, potentially leading to denial-of-service attacks. Linux kernel developers, maintainers, and users of Linux-based systems should assess exposure and apply patches to mitigate the risk.

  • Potential kernel crashes or instability due to NULL pointer dereferences
  • Increased risk of denial-of-service (DoS) attacks or system failures
  • Need for thorough testing and validation of kernel patches to ensure vulnerability fix

Technical summary

The Linux kernel's serial 8250 driver is vulnerable to a NULL pointer dereference when registering a serial port without a parent device. The driver's failure to handle NULL ->dev fields in both the uart slot and up structure leads to a kernel crash when has_acpi_companion() is called. This issue arises from the driver's failure to properly handle cases where both the existing uart slot and the up structure have a NULL ->dev field. As a result, the has_acpi_companion() function may dereference a NULL pointer, leading to a kernel crash. The vulnerability can cause system instability or crashes, potentially leading to denial-of-service attacks. Linux kernel developers, maintainers, and users of Linux-based The

Defensive priority

Medium

Recommended defensive actions

  • Review and apply the provided kernel patches to address the vulnerability
  • Ensure that all Linux kernel versions are up-to-date with the latest security patches
  • Monitor system logs for potential crashes or errors related to the serial 8250 driver
  • Perform thorough testing and validation of kernel patches to ensure vulnerability fix
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and source code analysis indicate a NULL pointer dereference vulnerability in the Linux kernel's serial 8250 driver. The issue is triggered when registering a serial port without a parent device, causing the has_acpi_companion() function to dereference a NULL pointer.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-97480 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-97480

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-97480 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97480

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/5cbab666721d974bfe033a12045d808936deaefd

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/941c9f84c9b6310f7aaa1c8c785dcc634ee33050

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.