What is CVE-2026-10674?
A vulnerability in the NXP LPUART serial driver (uart_mcux_lpuart.c) where LPUART_Deinit() disables peripheral clocks before configuration validation when CONFIG_UART_USE_RUNTIME_CONFIGURE is enabled. Affected systems should update the driver or apply the relevant kernel patch.
Azərbaycanca: CVE-2026-10674, NXP LPUART serial sürücüsündə (uart_mcux_lpuart.c) aşkar edilmiş zəiflikdir. CONFIG_UART_USE_RUNTIME_CONFIGURE aktiv olduqda, konfiqurasiya parametrlərinin doğrulanmasından əvvəl LPUART_Deinit() çağırışı ilə periferiya saatları söndürülür. Təsirə məruz qalan sistemlərdə sürücü yenilənməli və ya müvafiq kernel yaması tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-1188
FAQ2
Which kernel configuration must be enabled to be affected by CVE-2026-10674?
The vulnerability only occurs when CONFIG_UART_USE_RUNTIME_CONFIGURE is enabled.
What measures should be taken to remediate CVE-2026-10674?
Affected systems should update the NXP LPUART serial driver or apply the relevant kernel patch.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.