Answer in brief
CVE-2023-53094 records a High severity (CVSS 7.8) vulnerability in tty: serial: fsl_lpuart: fix race on RX DMA shutdown. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:linux:linux_kernel:6.3:rc1:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:linux:linux_kernel:6.3:rc2:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=4a8588a1cf867333187d9ff071e6fbdab587d194 <19a98d56dfedafb25652bdb9cd48a4e73ceba702 || >=4a8588a1cf867333187d9ff071e6fbdab587d194 <90530e7214c8a04dcdde57502d93fa96af288c38 || >=4a8588a1cf867333187d9ff071e6fbdab587d194 <954fc9931f0aabf272b5674cf468affdd88d3a36 || >=4a8588a1cf867333187d9ff071e6fbdab587d194 <2a36b444cace9580380467fd1183bb5e85bcc80a || >=4a8588a1cf867333187d9ff071e6fbdab587d194 <1be6f2b15f902c02e055ae0b419ca789200473c9 || 5716a781032693d0f812ed06528d98195e9df028 || 0d5cb6e8b4b62d8efd1a470615894276341d6db9 || >=3.18.9 <3.19 || >=3.19.1 <3.20 | 19a98d56dfedafb25652bdb9cd48a4e73ceba702, 90530e7214c8a04dcdde57502d93fa96af288c38, 954fc9931f0aabf272b5674cf468affdd88d3a36, 2a36b444cace9580380467fd1183bb5e85bcc80a, 1be6f2b15f902c02e055ae0b419ca789200473c9, 3.19, 3.20 |
| Linux/Linuxgeneric | 4.0 | Not reported |
Published upstream
May 2, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 4, 2026
In the Linux kernel, the following vulnerability has been resolved: tty: serial: fsl_lpuart: fix race on RX DMA shutdown From time to time DMA completion can come in the middle of DMA shutdown: <process ctx>: <IRQ>: lpuart32_shutdown() lpuart_dma_shutdown() del_timer_sync() lpuart_dma_rx_complete() lpuart_copy_rx_to_tty() mod_timer() lpuart_dma_rx_free() When the timer fires a bit later, sport->dma_rx_desc is NULL: Unable to handle kernel NULL pointer dereference at virtual address 0000000000000004 pc : lpuart_copy_rx_to_tty+0xcc/0x5bc lr : lpuart_timer_func+0x1c/0x2c Call trace: lpuart_copy_rx_to_tty lpuart_timer_func call_timer_fn __run_timers.part.0 run_timer_softirq __do_softirq __irq_exit_rcu irq_exit handle_domain_irq gic_handle_irq call_on_irq_stack do_interrupt_handler ... To fix this fold del_timer_sync() into lpuart_dma_rx_free() after dmaengine_terminate_sync() to make sure timer will not be re-started in lpuart_copy_rx_to_tty() <= lpuart_dma_rx_complete().
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2023-53094 records a High severity (CVSS 7.8) vulnerability in tty: serial: fsl_lpuart: fix race on RX DMA shutdown. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:linux:linux_kernel:6.3:rc1:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:linux:linux_kernel:6.3:rc2:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=4a8588a1cf867333187d9ff071e6fbdab587d194 <19a98d56dfedafb25652bdb9cd48a4e73ceba702 || >=4a8588a1cf867333187d9ff071e6fbdab587d194 <90530e7214c8a04dcdde57502d93fa96af288c38 || >=4a8588a1cf867333187d9ff071e6fbdab587d194 <954fc9931f0aabf272b5674cf468affdd88d3a36 || >=4a8588a1cf867333187d9ff071e6fbdab587d194 <2a36b444cace9580380467fd1183bb5e85bcc80a || >=4a8588a1cf867333187d9ff071e6fbdab587d194 <1be6f2b15f902c02e055ae0b419ca789200473c9 || 5716a781032693d0f812ed06528d98195e9df028 || 0d5cb6e8b4b62d8efd1a470615894276341d6db9 || >=3.18.9 <3.19 || >=3.19.1 <3.20 | 19a98d56dfedafb25652bdb9cd48a4e73ceba702, 90530e7214c8a04dcdde57502d93fa96af288c38, 954fc9931f0aabf272b5674cf468affdd88d3a36, 2a36b444cace9580380467fd1183bb5e85bcc80a, 1be6f2b15f902c02e055ae0b419ca789200473c9, 3.19, 3.20 |
| Linux/Linuxgeneric | 4.0 | Not reported |
Published upstream
May 2, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 4, 2026
In the Linux kernel, the following vulnerability has been resolved: tty: serial: fsl_lpuart: fix race on RX DMA shutdown From time to time DMA completion can come in the middle of DMA shutdown: <process ctx>: <IRQ>: lpuart32_shutdown() lpuart_dma_shutdown() del_timer_sync() lpuart_dma_rx_complete() lpuart_copy_rx_to_tty() mod_timer() lpuart_dma_rx_free() When the timer fires a bit later, sport->dma_rx_desc is NULL: Unable to handle kernel NULL pointer dereference at virtual address 0000000000000004 pc : lpuart_copy_rx_to_tty+0xcc/0x5bc lr : lpuart_timer_func+0x1c/0x2c Call trace: lpuart_copy_rx_to_tty lpuart_timer_func call_timer_fn __run_timers.part.0 run_timer_softirq __do_softirq __irq_exit_rcu irq_exit handle_domain_irq gic_handle_irq call_on_irq_stack do_interrupt_handler ... To fix this fold del_timer_sync() into lpuart_dma_rx_free() after dmaengine_terminate_sync() to make sure timer will not be re-started in lpuart_copy_rx_to_tty() <= lpuart_dma_rx_complete().
Quoted source text, attributed separately from HOL analysis.