Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-74654

Published Aug 22, 2026 EPSS 0.18% (7th pctl)

Overview

CVE-2026-74654 is a known-severity vulnerability. It was published on August 22, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

serial: 8250_dma: Clear stale RX state on shutdown

serial8250_release_dma() terminates RX DMA and releases the channel, but

leaves rx_running set. If the port is closed while an RX transfer is

active, the stale state remains while rxchan is NULL until the channel is

requested again on the next open.

The DesignWare BUSY workaround added by commit a7b9ce39fbe4

("serial: 8250_dw: Ensure BUSY is deasserted") calls

serial8250_rx_dma_flush() from the LCR write path during startup. This

happens before serial8250_request_dma() obtains a new RX channel. On

reopen, the stale rx_running state therefore makes the flush path pass a

NULL channel to dmaengine_pause(), causing a kernel Oops.

Clear rx_running after terminating RX DMA, matching the TX cleanup. Also

make the flush helper return if the DMA object or RX channel is not

available so startup and teardown paths cannot pass a NULL channel to the

DMAengine API.

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-74654?

CVE-2026-74654 is a known-severity vulnerability. It was published on August 22, 2026.

How severe is CVE-2026-74654?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-74654?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-74654?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-74654 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.