PT-2026-61200 · Linux · Linux
CVE-2026-63883
·
Publicado
2026-07-19
·
Atualizado
2026-07-19
CVSS v3.1
7.3
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L |
In the Linux kernel, the following vulnerability has been resolved:
serial: qcom geni: fix kfifo underflow when flush precedes DMA completion IRQ
When uart flush buffer() runs before the DMA completion IRQ is delivered,
the following race can occur (all steps serialized by uart port lock):
- DMA starts: tx remaining = N, kfifo contains N bytes
- DMA completes in hardware; IRQ is pending but not yet delivered
- uart flush buffer() acquires the port lock and calls kfifo reset(), making kfifo len() = 0 while tx remaining remains N
- uart flush buffer() releases the port lock
- DMA IRQ fires; handle tx dma() acquires the port lock and calls uart xmit advance(uport, tx remaining) on an empty kfifo
uart xmit advance() increments kfifo->out by tx remaining. Since
kfifo reset() already set both in and out to 0, out wraps past in,
causing kfifo len() to return UART XMIT SIZE - tx remaining. The next
start tx dma() call then submits a DMA transfer of stale buffer data.
Fix this by snapshotting kfifo len() at the start of handle tx dma()
and skipping uart xmit advance() when fifo len < tx remaining, which
indicates the kfifo was reset by a preceding flush.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux