In the Linux kernel, the following vulnerability has been resolved:
serial: dz: Convert to use a platform device
Prevent a crash from happening as the first serial port is initialised:
Console: switching to colour frame buffer device 160x64 tgafb: SFB+ detected, rev=0x02 fb0: Digital ZLX-E1 frame buffer device at 0x1e000000 DECstation DZ serial driver version 1.04 CPU 0 Unable to handle kernel paging request at virtual address 000000bc, epc == 8048b3a4, ra == 80470a78 Oops[#1]: CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.19.0-dirty #35 NONE $ 0 : 00000000 1000ac00 00000004 804707ac $ 4 : 00000000 80e20850 80e20858 81000030 $ 8 : 00000000 8072c81c 00000008 fefefeff $12 : 6c616972 00000006 80c5917f 69726420 $16 : 80e20800 00000000 808f8968 80e20800 $20 : 00000000 807f5a90 808b0094 808d3bc8 $24 : 00000018 80479030 $28 : 80c2e000 80c2fd70 00000069 80470a78 Hi : 00000004 Lo : 00000000 epc : 8048b3a4 __dev_fwnode+0x0/0xc ra : 80470a78 serial_base_ctrl_add+0xa0/0x168 Status: 1000ac04 IEp Cause : 30000008 (ExcCode 02) BadVA : 000000bc PrId : 00000220 (R3000) Modules linked in: Process swapper/0 (pid: 1, threadinfo=(ptrval), task=(ptrval), tls=00000000) Stack : 00400044 00400040 8046f4cc 00000000 808a6148 808a0000 808f8968 8086983c 808e0000 8046fc84 1000ac01 00000028 80e20700 802ba3f8 80e20700 80d34a94 80c1b900 80e20700 80e20700 80e20700 80e20700 80444650 00000000 00000000 00000000 807f5a90 808b0094 80447080 00400040 808e0000 80d34a94 808a6148 80d34a94 00000004 80e20700 00000000 8076974c 80469810 80c2fe3c 1000ac01 ... Call Trace: [<8048b3a4>] __dev_fwnode+0x0/0xc [<80470a78>] serial_base_ctrl_add+0xa0/0x168 [<8046fc84>] serial_core_register_port+0x1c8/0x974 [<808c6af0>] dz_init+0x74/0xc8 [<800470e0>] do_one_initcall+0x44/0x2d4 [<808b111c>] kernel_init_freeable+0x258/0x308 [<8072e434>] kernel_init+0x20/0x114 [<80049cd0>] ret_from_kernel_thread+0x14/0x1c
Code: 27bd0018 03e00008 2402ffea <8c8200bc> 03e00008 00000000 27bdffc0 afbe0038 afb30024
---[ end trace 0000000000000000 ]---
-- where a pointer is dereferenced that has been derived from a null pointer to the port's parent device.
Since no device is available with legacy probing and it's not anymore a preferable way to discover devices anyway, switch the driver to using a platform device and use it as the port's parent device. Update resource handling accordingly and only request the actual span of addresses used within the slot, which will have had its resource already requested by generic platform device code.
Use platform_driver_probe() not just because the DZ device is fixed with solder on board and not straightforward to remove, but foremost because the associated TTY's major device number is the same as used by the zs driver and the first driver to claim it will prevent the other one from using it. Either one DZ device or some SCC devices will be present in a given system but never both at a time, and therefore we want the major device number to be claimed by the first driver to actually successfully bind to its device and platform_driver_probe() is a way to fulfil that.
An unfortunate consequence of the switch to a platform device is we now hand the console over from the bootconsole much later in the bootstrap. The firmware console handler appears good enough though to work so late and in particular with interrupts enabled.
Conversely only starting the console port so late lets the reset code fully utilise our delay handlers, so switch from udelay() to fsleep() for transmitter draining so as to avoid busy-waiting for an excessive amount of time.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade kernel-livepatch-6.12.94-123.174Upgrade kernel6.12-debuginfo-common-x86_64Upgrade kernel6.18-debuginfo-common-aarch64Upgrade python3-perf6.12Upgrade kernel6.12-modules-extraUpgrade kernel6.18-tools-debuginfoUpgrade perf6.18-debuginfoUpgrade kernel6.12-toolsUpgrade kernel6.12Upgrade kernel6.12-tools-develUpgrade kernel6.18-headersUpgrade bpftool6.12Upgrade kernel6.18-toolsUpgrade bpftool6.18-debuginfoUpgrade perf6.12-debuginfoUpgrade kernel6.18-debuginfoUpgrade perf6.12Upgrade kernel6.12-debuginfo-common-aarch64Upgrade kernel6.12-modules-extra-commonUpgrade python3-perf6.18-debuginfoUpgrade bpftool6.12-debuginfoUpgrade kernel6.18Upgrade kernel6.12-develUpgrade kernel6.18-modules-extraUpgrade kernel6.18-develUpgrade kernel6.12-tools-debuginfoUpgrade kernel-livepatch-6.18.35-68.127Upgrade perf6.18Upgrade microvm-kernel6.18Upgrade kernel6.12-debuginfoUpgrade kernel6.18-tools-develUpgrade kernel6.18-debuginfo-common-x86_64Upgrade python3-perf6.18Upgrade kernel6.18-modules-extra-commonUpgrade kernel6.12-headersUpgrade bpftool6.18Upgrade python3-perf6.12-debuginfo | Aug 10, 2026 | Jul 19, 2026 |
| Debian | — | Upgrade linux | Jul 23, 2026 | Jul 23, 2026 |
| Ubuntu | — | Upgrade linux-image-aws-64k-7.0Upgrade linux-image-aws-64kUpgrade linux-image-nvidia-64kUpgrade linux-image-7.0.0-1010-azureUpgrade linux-image-nvidia-64k-hwe-26.04Upgrade linux-image-aws-7.0Upgrade linux-image-nvidiaUpgrade linux-image-7.0.0-1009-aws-64kUpgrade linux-image-7.0.0-2016-nvidia-bos-64kUpgrade linux-image-gcpUpgrade linux-image-oracle-64kUpgrade linux-image-raspi-realtimeUpgrade linux-image-7.0.0-1016-nvidia-64kUpgrade linux-image-oracle-64k-7.0Upgrade linux-image-7.0.0-1015-raspiUpgrade linux-image-7.0.0-1010-ibmUpgrade linux-image-nvidia-hwe-26.04Upgrade linux-image-7.0.0-1009-azure-fdeUpgrade linux-image-nvidia-bos-64kUpgrade linux-image-ibm-7.0Upgrade linux-image-gcp-64k-7.0Upgrade linux-image-nvidia-bos-7.0Upgrade linux-image-raspi-realtime-7.0Upgrade linux-image-7.0.0-1014-azureUpgrade linux-image-azure-fde-7.0Upgrade linux-image-nvidia-bos-64k-7.0Upgrade linux-image-nvidia-7.0Upgrade linux-image-nvidia-64k-7.0Upgrade linux-image-oracle-7.0Upgrade linux-image-azureUpgrade linux-image-ibmUpgrade linux-image-azure-fdeUpgrade linux-image-7.0.0-2016-nvidia-bosUpgrade linux-image-azure-7.0Upgrade linux-image-7.0.0-1016-nvidiaUpgrade linux-image-7.0.0-1009-awsUpgrade linux-image-7.0.0-1008-oracleUpgrade linux-image-nvidia-bosUpgrade linux-image-gcp-7.0Upgrade linux-image-gcp-64kUpgrade linux-image-7.0.0-1008-oracle-64kUpgrade linux-image-raspi-7.0Upgrade linux-image-awsUpgrade linux-image-7.0.0-1015-raspi-realtimeUpgrade linux-image-raspiUpgrade linux-image-7.0.0-1011-gcp-64kUpgrade linux-image-oracleUpgrade linux-image-7.0.0-1011-gcp | Jul 21, 2026 | Jul 20, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 5, 2026 | Jul 19, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub