---
id: CVE-2026-23472
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN

  uart_write_room() and uart_write() behave inconsistently when
  xmit_buf is NULL (which happens for PORT_…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN

  uart_write_room() and uart_write() behave inconsistently when
  xmit_buf is NULL (which happens for PORT_…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-835
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 2.6.12.1, < 6.18.20'
  - 'linux_kernel >= 6.19, < 6.19.10'
  - linux_kernel = 2.6.12
  - linux_kernel = 7.0
patched:
  - linux_kernel 6.19.10
published: '2026-04-03'
updated: '2026-07-20'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-23472'
references:
  - url: 'https://git.kernel.org/stable/c/455ce986fa356ff43a43c0d363ba95fa152f21d5'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/bc70f2b36cf474d5cc8ecbcaf57f3e326fdec67c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/efe85a557186b7fe915572ae93a8f3f78bfd9a22'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00121
epssPercentile: 0.01677
ingestedAt: '2026-07-21T16:51:40.572Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN

uart_write_room() and uart_write() behave inconsistently when
xmit_buf is NULL (which happens for PORT_UNKNOWN ports that were
never properly initialized):

- uart_write_room() returns kfifo_avail() which can be > 0
- uart_write() checks xmit_buf and returns 0 if NULL

This inconsistency causes an infinite loop in drivers that rely on
tty_write_room() to determine if they can write:

  while (tty_write_room(tty) > 0) {
      written = tty->ops->write(...);
      // written is always 0, loop never exits
  }

For example, caif_serial's handle_tx() enters an infinite loop when
used with PORT_UNKNOWN serial ports, causing system hangs.

Fix by making uart_write_room() also check xmit_buf and return 0 if
it's NULL, consistent with uart_write().

Reproducer: https://gist.github.com/mrpre/d9a694cc0e19828ee3bc3b37983fde13

## Affected

- `linux_kernel >= 2.6.12.1, < 6.18.20`
- `linux_kernel >= 6.19, < 6.19.10`
- `linux_kernel = 2.6.12`
- `linux_kernel = 7.0`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.19.10`
