{"id":"DEBIAN-CVE-2025-38262","details":"In the Linux kernel, the following vulnerability has been resolved:  tty: serial: uartlite: register uart driver in init  When two instances of uart devices are probing, a concurrency race can occur. If one thread calls uart_register_driver function, which first allocates and assigns memory to 'uart_state' member of uart_driver structure, the other instance can bypass uart driver registration and call ulite_assign. This calls uart_add_one_port, which expects the uart driver to be fully initialized. This leads to a kernel panic due to a null pointer dereference:  [    8.143581] BUG: kernel NULL pointer dereference, address: 00000000000002b8 [    8.156982] #PF: supervisor write access in kernel mode [    8.156984] #PF: error_code(0x0002) - not-present page [    8.156986] PGD 0 P4D 0 ... [    8.180668] RIP: 0010:mutex_lock+0x19/0x30 [    8.188624] Call Trace: [    8.188629]  ? __die_body.cold+0x1a/0x1f [    8.195260]  ? page_fault_oops+0x15c/0x290 [    8.209183]  ? __irq_resolve_mapping+0x47/0x80 [    8.209187]  ? exc_page_fault+0x64/0x140 [    8.209190]  ? asm_exc_page_fault+0x22/0x30 [    8.209196]  ? mutex_lock+0x19/0x30 [    8.223116]  uart_add_one_port+0x60/0x440 [    8.223122]  ? proc_tty_register_driver+0x43/0x50 [    8.223126]  ? tty_register_driver+0x1ca/0x1e0 [    8.246250]  ulite_probe+0x357/0x4b0 [uartlite]  To prevent it, move uart driver registration in to init function. This will ensure that uart_driver is always registered when probe function is called.","modified":"2026-09-01T16:06:14.128889756Z","published":"2025-07-09T11:15:28.570Z","upstream":["CVE-2025-38262"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-38262"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.147-1"}]}],"versions":["6.1.106-1","6.1.106-2","6.1.106-3","6.1.112-1","6.1.115-1","6.1.119-1","6.1.123-1","6.1.124-1","6.1.128-1","6.1.129-1","6.1.133-1","6.1.135-1","6.1.137-1","6.1.139-1","6.1.140-1","6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38262.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.37-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38262.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.37-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38262.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}