CVE-2026-74652
Last modified
CVE-2026-74652 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: serial: amba-pl011: cancel RS485 hrtimers after freeing IRQ The RS485 trigger hrtimers are embedded in the devm-managed port and can fire after it is freed. The IRQ handler can arm a timer, so free the IRQ first and then cancel both timers. Complete the RS485 stop without arming a timer, and cancel the timers in remove() for the suspend-then-unbind path, where shutdown is not called. This issue was found by an in-house static analysis tool..
Description
In the Linux kernel, the following vulnerability has been resolved: serial: amba-pl011: cancel RS485 hrtimers after freeing IRQ The RS485 trigger hrtimers are embedded in the devm-managed port and can fire after it is freed. The IRQ handler can arm a timer, so free the IRQ first and then cancel both timers. Complete the RS485 stop without arming a timer, and cancel the timers in remove() for the suspend-then-unbind path, where shutdown is not called. This issue was found by an in-house static analysis tool.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 2c1fd53af21b8cb13878b054894d33d3383eb1f3, < 759ead98a39fb625be302f9aa66290985dcaa325; >= 2c1fd53af21b8cb13878b054894d33d3383eb1f3, < e57f0aa5c35be37218ba0e4887b241584dd4b2d2; >= 2c1fd53af21b8cb13878b054894d33d3383eb1f3, < 36672c8d7d14e9c43287528455d2c97b526ea6ad |
| Linux | Linux | 6.14 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-74652?
How severe is CVE-2026-74652?
How do I fix CVE-2026-74652?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-74647In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74648In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74649In the Linux kernel, the following vulnerability has been re…
- CVE-2026-7465The Spectra Gutenberg Blocks – Website Builder for the Block…8.8
- CVE-2026-74650In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74651In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74653In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74654In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74655In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74656In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74657In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74658In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-74652?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
