CVE-2026-63877

UNRATEDCVSS · not yet scoredTrending — 3 sources updated this week
EchelonGraph verdictMonitorLow exploitation likelihood right now — keep watching.
  • No CVSS published and no exploitation signals yet
CISA-KEV: Not listedEPSS PROB: 0%CVSS v2: Exploit: None knownExposed: 0

A fix is available — apply it.

In the Linux kernel, the following vulnerability has been resolved:

serial: dz: Convert to use a platform device

Prevent a crash from happening as the first serial port is initialised:

Console: switching to colour frame buffer device 160x64 tgafb: SFB+ detected, rev=0x02 fb0: Digital ZLX-E1 frame buffer device at 0x1e000000 DECstation DZ serial driver version 1.04 CPU 0 Unable to handle kernel paging request at virtual address 000000bc, epc == 8048b3a4, ra == 80470a78 Oops[#1]: CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.19.0-dirty #35 NONE $ 0 : 00000000 1000ac00 00000004 804707ac $ 4 : 00000000 80e20850 80e20858 81000030 $ 8 : 00000000 8072c81c 00000008 fefefeff $12 : 6c616972 00000006 80c5917f 69726420 $16 : 80e20800 00000000 808f8968 80e20800 $20 : 00000000 807f5a90 808b0094 808d3bc8 $24 : 00000018 80479030 $28 : 80c2e000 80c2fd70 00000069 80470a78 Hi : 00000004 Lo : 00000000 epc : 8048b3a4 __dev_fwnode+0x0/0xc ra : 80470a78 serial_base_ctrl_add+0xa0/0x168 Status: 1000ac04 IEp Cause : 30000008 (ExcCode 02) BadVA : 000000bc PrId : 00000220 (R3000) Modules linked in: Process swapper/0 (pid: 1, threadinfo=(ptrval), task=(ptrval), tls=00000000) Stack : 00400044 00400040 8046f4cc 00000000 808a6148 808a0000 808f8968 8086983c 808e0000 8046fc84 1000ac01 00000028 80e20700 802ba3f8 80e20700 80d34a94 80c1b900 80e20700 80e20700 80e20700 80e20700 80444650 00000000 00000000 00000000 807f5a90 808b0094 80447080 00400040 808e0000 80d34a94 808a6148 80d34a94 00000004 80e20700 00000000 8076974c 80469810 80c2fe3c 1000ac01 ... Call Trace: [<8048b3a4>] __dev_fwnode+0x0/0xc [<80470a78>] serial_base_ctrl_add+0xa0/0x168 [<8046fc84>] serial_core_register_port+0x1c8/0x974 [<808c6af0>] dz_init+0x74/0xc8 [<800470e0>] do_one_initcall+0x44/0x2d4 [<808b111c>] kernel_init_freeable+0x258/0x308 [<8072e434>] kernel_init+0x20/0x114 [<80049cd0>] ret_from_kernel_thread+0x14/0x1c

Code: 27bd0018 03e00008 2402ffea <8c8200bc> 03e00008 00000000 27bdffc0 afbe0038 afb30024

---[ end trace 0000000000000000 ]---

-- where a pointer is dereferenced that has been derived from a null pointer to the port's parent device.

Since no device is available with legacy probing and it's not anymore a preferable way to discover devices anyway, switch the driver to using a platform device and use it as the port's parent device. Update resource handling accordingly and only request the actual span of addresses used within the slot, which will have had its resource already requested by generic platform device code.

Use platform_driver_probe() not just because the DZ device is fixed with solder on board and not straightforward to remove, but foremost because the associated TTY's major device number is the same as used by the zs driver and the first driver to claim it will prevent the other one from using it. Either one DZ device or some SCC devices will be present in a given system but never both at a time, and therefore we want the major device number to be claimed by the first driver to actually successfully bind to its device and platform_driver_probe() is a way to fulfil that.

An unfortunate consequence of the switch to a platform device is we now hand the console over from the bootconsole much later in the bootstrap. The firmware console handler appears good enough though to work so late and in particular with interrupts enabled.

Conversely only starting the console port so late lets the reset code fully utilise our delay handlers, so switch from udelay() to fsleep() for transmitter draining so as to avoid busy-waiting for an excessive amount of time.

CVSS v3
EchelonGraph score
Not yet assessedNo source has published severity data for this CVE yet — no CVSS score from NVD or a CNA, no GitHub advisory, and it is not in CISA KEV. This is not a rating of zero; we cannot assess it yet.
EG Score
EG Risk
EPSS PROB
0%
EPSS %ILE
12%
KEV
Not listed

Published

July 19, 2026

Last Modified

July 27, 2026

Vendor Advisories for CVE-2026-63877(1)

These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.

Patch Availability(5)

Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.

Affected Packages

(2 across 2 ecosystems)
Debian:13(1)
PackageVulnerable rangeFixed inDependents
linux6.12.38-1 ... 6.12.94-1~bpo12+1 (27 versions)6.12.94-1
Debian:14(1)
PackageVulnerable rangeFixed inDependents
linux6.12.100-1 ... 7.0.9-1~bpo13+1 (138 versions)7.0.12-1

All Vendor Advisories

(5)

Data Freshness Timeline

(refreshed 9× in last 7d / 44× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

  1. 2026-08-30 02:59 UTCVendor advisory
  2. 2026-08-30 02:59 UTCGHSA enrichment
  3. 2026-08-30 01:22 UTCEPSS rescore
  4. 2026-08-28 21:42 UTCEPSS rescore
  5. 2026-08-27 14:25 UTCEPSS rescore
  6. 2026-08-26 14:46 UTCEPSS rescore
  7. 2026-08-25 15:52 UTCVendor advisory
  8. 2026-08-25 15:52 UTCGHSA enrichment
  9. 2026-08-25 13:49 UTCEPSS rescore
  10. 2026-08-23 00:19 UTCEPSS rescore
  11. 2026-08-22 10:47 UTCVendor advisory
  12. 2026-08-22 10:47 UTCGHSA enrichment
  13. 2026-08-21 23:49 UTCEPSS rescore
  14. 2026-08-20 22:55 UTCEPSS rescore
  15. 2026-08-19 17:04 UTCEPSS rescore
  16. 2026-08-19 05:40 UTCVendor advisory
  17. 2026-08-19 05:40 UTCGHSA enrichment
  18. 2026-08-18 13:48 UTCEPSS rescore
  19. 2026-08-17 13:47 UTCEPSS rescore
  20. 2026-08-16 14:56 UTCEPSS rescore
  21. 2026-08-16 00:34 UTCVendor advisory
  22. 2026-08-16 00:34 UTCGHSA enrichment
  23. 2026-08-15 01:30 UTCEPSS rescore
  24. 2026-08-13 22:00 UTCEPSS rescore
  25. 2026-08-12 19:27 UTCVendor advisory
Show 50 more
  1. 2026-08-12 19:27 UTCGHSA enrichment
  2. 2026-08-12 13:51 UTCEPSS rescore
  3. 2026-08-11 00:00 UTCEPSS rescore
  4. 2026-08-09 14:21 UTCVendor advisory
  5. 2026-08-09 14:21 UTCGHSA enrichment
  6. 2026-08-09 13:47 UTCEPSS rescore
  7. 2026-08-08 16:37 UTCEPSS rescore
  8. 2026-08-06 13:47 UTCEPSS rescore
  9. 2026-08-06 09:15 UTCVendor advisory
  10. 2026-08-06 09:15 UTCGHSA enrichment
  11. 2026-08-05 19:17 UTCEPSS rescore
  12. 2026-08-05 19:17 UTCEPSS rescore
  13. 2026-08-04 15:10 UTCEPSS rescore
  14. 2026-08-04 10:39 UTCEPSS rescore
  15. 2026-08-03 10:36 UTCEPSS rescore
  16. 2026-08-03 04:10 UTCVendor advisory
  17. 2026-08-03 04:10 UTCGHSA enrichment
  18. 2026-08-02 02:27 UTCEPSS rescore
  19. 2026-08-01 04:16 UTCEPSS rescore
  20. 2026-07-30 22:58 UTCEG score recompute
  21. 2026-07-30 22:58 UTCVendor advisory
  22. 2026-07-30 22:58 UTCGHSA enrichment
  23. 2026-07-30 16:28 UTCEPSS rescore
  24. 2026-07-30 01:30 UTCEPSS rescore
  25. 2026-07-30 01:30 UTCEPSS rescore
  26. 2026-07-28 15:37 UTCEPSS rescore
  27. 2026-07-27 17:51 UTCGHSA enrichment
  28. 2026-07-27 14:14 UTCEPSS rescore
  29. 2026-07-26 14:54 UTCEPSS rescore
  30. 2026-07-26 14:54 UTCEPSS rescore
  31. 2026-07-26 11:02 UTCEG score recompute
  32. 2026-07-26 11:02 UTCVendor advisory
  33. 2026-07-26 11:02 UTCGHSA enrichment
  34. 2026-07-25 14:18 UTCEPSS rescore
  35. 2026-07-25 14:18 UTCEPSS rescore
  36. 2026-07-24 14:18 UTCEPSS rescore
  37. 2026-07-24 14:18 UTCEPSS rescore
  38. 2026-07-23 14:18 UTCEPSS rescore
  39. 2026-07-23 14:18 UTCEPSS rescore
  40. 2026-07-23 03:22 UTCEG score recompute
  41. 2026-07-22 14:08 UTCEPSS rescore
  42. 2026-07-22 14:08 UTCEPSS rescore
  43. 2026-07-21 15:25 UTCEPSS rescore
  44. 2026-07-21 15:25 UTCEPSS rescore
  45. 2026-07-20 17:39 UTCEG score recompute
  46. 2026-07-20 17:39 UTCGHSA enrichment
  47. 2026-07-20 17:08 UTCEPSS rescore
  48. 2026-07-19 17:49 UTCNVD update
  49. 2026-07-19 15:24 UTCEG score recompute
  50. 2026-07-19 15:19 UTCMITRE cvelistV5first tracked

Frequently asked(4)

What is CVE-2026-63877?
CVE-2026-63877 is a publicly disclosed vulnerability published on July 19, 2026. In the Linux kernel, the following vulnerability has been resolved: serial: dz: Convert to use a platform device Prevent a crash from happening as the first serial port is initialised: Console: switching to colour frame buffer device 160x64 tgafb: SFB+ detected, rev=0x02 fb0: Digital ZLX-E1 frame…
When was CVE-2026-63877 disclosed?
CVE-2026-63877 was first published in the National Vulnerability Database on July 19, 2026, with the most recent update on July 27, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2026-63877 actively exploited?
CVE-2026-63877 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 0% probability of exploitation in the next 30 days, which ranks it in the top 87.9% of all scored CVEs.
How do I remediate CVE-2026-63877?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2026-63877, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.

Dependency Blast Radius

See which npm, PyPI, Go, and Maven packages are affected by CVE-2026-63877

Explore →

Is Your Infrastructure Affected by CVE-2026-63877?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.