0.0
NA
CVE-2026-80737
serial: amba-pl011: synchronize DMA teardown
Description

In the Linux kernel, the following vulnerability has been resolved: serial: amba-pl011: synchronize DMA teardown dmaengine_terminate_all() does not wait for a running callback, so the TX callback can still touch the TX buffer after it is freed. The RX poll timer reads the RX buffers without the port lock. Switch to dmaengine_terminate_sync() and delete the RX timer before freeing the buffers.

INFO

Published Date :

Sept. 3, 2026, 8:21 a.m.

Last Modified :

Sept. 3, 2026, 8:21 a.m.

Remotely Exploit :

No

Source :

Linux
Affected Products

The following products are affected by CVE-2026-80737 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
Solution
Fix race condition by using dmaengine_terminate_sync and deleting RX timer before freeing buffers.
  • Use dmaengine_terminate_sync instead of dmaengine_terminate_all.
  • Delete the RX timer before freeing TX buffers.
  • Ensure TX callback does not touch freed buffers.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-80737 vulnerability anywhere in the article.

EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.