CVE-2025-38262 Details
Description
In the Linux kernel, the following vulnerability has been resolved: tty: serial: uartlite: register uart driver in init When two instances of uart devices are probing, a concurrency race can occur. If one thread calls uart_register_driver function, which first allocates and assigns memory to 'uart_state' member of uart_driver structure, the other instance can bypass uart driver registration and call ulite_assign. This calls uart_add_one_port, which expects the uart driver to be fully initialized. This leads to a kernel panic due to a null pointer dereference: [ 8.143581] BUG: kernel NULL pointer dereference, address: 00000000000002b8 [ 8.156982] #PF: supervisor write access in kernel mode [ 8.156984] #PF: error_code(0x0002) - not-present page [ 8.156986] PGD 0 P4D 0 ... [ 8.180668] RIP: 0010:mutex_lock+0x19/0x30 [ 8.188624] Call Trace: [ 8.188629] ? __die_body.cold+0x1a/0x1f [ 8.195260] ? page_fault_oops+0x15c/0x290 [ 8.209183] ? __irq_resolve_mapping+0x47/0x80 [ 8.209187] ? exc_page_fault+0x64/0x140 [ 8.209190] ? asm_exc_page_fault+0x22/0x30 [ 8.209196] ? mutex_lock+0x19/0x30 [ 8.223116] uart_add_one_port+0x60/0x440 [ 8.223122] ? proc_tty_register_driver+0x43/0x50 [ 8.223126] ? tty_register_driver+0x1ca/0x1e0 [ 8.246250] ulite_probe+0x357/0x4b0 [uartlite] To prevent it, move uart driver registration in to init function. This will ensure that uart_driver is always registered when probe function is called.
A concurrency race vulnerability has been identified in the Linux kernel's handling of UART device driver registration. When two UART device instances are probed simultaneously, a race condition can occur. One thread may initiate the driver registration process by calling the 'uart_register_driver' function, which allocates memory for the 'uart_state' member of the 'uart_driver' structure. Meanwhile, another instance can bypass this registration and invoke 'ulite_assign', which calls 'uart_add_one_port'. This function expects the UART driver to be fully initialized, but the race condition can lead to a null pointer dereference, causing a kernel panic. The issue arises because the driver registration is not completed before the probe function is called, creating a timing conflict that can be exploited.
The vulnerability can be addressed by modifying the driver registration process to ensure it is completed before the probe function is called. This can be done by moving the registration into the initialization function of the driver.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/5015eed450005bab6e5cb6810f7a62eab0434fc4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/685d29f2c5057b32c7b1b46f2a7d303b926c8f72 | kernel.org | Patch |
| https://git.kernel.org/stable/c/6bd697b5fc39fd24e2aa418c7b7d14469f550a93 | kernel.org | Patch |
| https://git.kernel.org/stable/c/6db06aaea07bb7c8e33a425cf7b98bf29ee6056e | kernel.org | Patch |
| https://git.kernel.org/stable/c/8e958d10dd0ce5ae674cce460db5c9ca3f25243b | kernel.org | Patch |
| https://git.kernel.org/stable/c/9c905fdbba68a6d73d39a6b7de9b9f0d6c46df87 | kernel.org | Patch |
| https://git.kernel.org/stable/c/f5e4229d94792b40e750f30c92bcf7a3107c72ef | kernel.org | Patch |
| https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html | CVE | Mailing ListThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 2.6.20, < 5.4.296 >= 5.5, < 5.15.187 >= 5.16, < 6.1.143 >= 6.2, < 6.6.96 >= 6.7, < 6.12.36 >= 6.13, < 6.15.5 |
CPE
Remediation
| |
| debian debian linux | 11.0 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 30, 2026 | CVE Modified | kernel.org |
| Jun 17, 2026 | CVE Modified | kernel.org |
| Dec 18, 2025 | Initial Analysis | [email protected] |
| Nov 3, 2025 | CVE Modified | CVE |
| Jul 17, 2025 | CVE Modified | kernel.org |
| Jul 10, 2025 | CVE Modified | kernel.org |
| Jul 9, 2025 | New CVE Received | kernel.org |