Overview: CVE-2026-23115 addresses a race condition in the Linux kernel's serial driver, specifically affecting how tty devices are linked to their ports. This vulnerability occurs when user-space attempts to open a console before the tty->port is properly configured, leading to a kernel crash. It primarily impacts systems using Qualcomm SoCs with fast boot sequences and a serial console. Severity: The vulnerability has a FAUCET Risk Score of 20/100, indicating a low to moderate severity. The attack vector is local, requiring user-space interaction to trigger the race condition. The complexity is relatively low, as it can be consistently reproduced under specific boot conditions. The potential impact is a kernel crash, leading to system instability and denial of service. Exploitation Status: There is no evidence of active exploitation for CVE-2026-23115. No exploit code is publicly available on platforms like Metasploit, Nuclei, or ExploitDB. Community attention and media coverage are minimal, with zero mentions on social media or in news articles, suggesting it is not a widely discussed or exploited vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.15, < 6.18.8CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.19CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.19:rc1:*:*:*:*:*:* | ||
6.19CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.19:rc2:*:*:*:*:*:* | ||
6.19CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.19:rc3:*:*:*:*:*:* | ||
6.19CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.19:rc4:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel (Azure CVM) vulnerabilities
Jul 24, 2026Linux kernel (Azure) vulnerabilities
Jul 24, 2026Linux kernel (OEM) vulnerabilities
Jul 23, 2026Linux kernel vulnerabilities
Jul 20, 2026kernel: serial: Fix not set tty->port race condition
Feb 14, 2026