PT-2026-55697 · Linux+1 · Linux Kernel+1

·

CVE-2026-53359

·

Published

2026-06-12

·

Updated

2026-07-30

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free issue exists in the x86 shadow MMU of the Kernel-based Virtual Machine (KVM) subsystem. The flaw occurs in the rmap remove() function when a Page Directory Entry (PDE) mapping is changed from outside the guest and a memslot is subsequently deleted. Specifically, if a modified PDE points to a non-leaf page, the kvm mmu get child sp() function fails to compare the role of the page, leading to the reuse of a page with an incorrect role (e.g., a 2MB page with direct=1 instead of a 4KB page with direct=0). When the child is zapped, kvm mmu page get gfn() computes an incorrect Guest Frame Number (GFN), causing the system to fail to remove the recorded rmap entry. Consequently, when the memslot is dropped, the shadow page is freed while the rmap entry survives. Subsequent operations, such as dirty logging or MMU notifier invalidation, dereference a pointer to the freed page. This can be exploited by a guest VM with root privileges to cause a host kernel panic (denial of service) or achieve guest-to-host escape to execute arbitrary code with root privileges on the host system. The issue affects both Intel and AMD x86 architectures.
Recommendations Update the Linux kernel to versions 7.1.3, 6.18.38, 6.12.95, 6.6.144, 6.1.177, 5.15.211, or 5.10.260. As a mitigation measure, disable nested virtualization by setting kvm intel.nested=0 and kvm amd.nested=0 in the kernel arguments.

Exploit

Fix

LPE

DoS

RCE

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:36956
ALSA-2026:36957
ALSA-2026:39082
ALSA-2026:39083
BDU:2026-09298
CVE-2026-53359
ECHO-CA58-2059-36E1
OPENSUSE-SU-2026:11214-1
OPENSUSE-SU-2026:21388-1
RHSA-2026:39371
RHSA-2026:39983
RHSA-2026:40082
RHSA-2026:41229
RHSA-2026:43847
RHSA-2026:44003
RHSA-2026:44004
SUSE-SU-2026:22521-1
SUSE-SU-2026:22522-1
SUSE-SU-2026:22665-1
SUSE-SU-2026:22666-1
SUSE-SU-2026:22742-1
SUSE-SU-2026:22769-1
SUSE-SU-2026:22809-1
SUSE-SU-2026:22810-1
SUSE-SU-2026:22812-1
SUSE-SU-2026:22835-1
SUSE-SU-2026:22903-1
SUSE-SU-2026:22904-1
SUSE-SU-2026:22961-1
SUSE-SU-2026:22962-1
SUSE-SU-2026:22963-1
SUSE-SU-2026:22964-1
SUSE-SU-2026:22965-1
SUSE-SU-2026:22966-1
SUSE-SU-2026:22967-1
SUSE-SU-2026:22968-1
SUSE-SU-2026:22969-1
SUSE-SU-2026:22970-1
SUSE-SU-2026:22971-1
SUSE-SU-2026:22972-1
SUSE-SU-2026:22973-1
SUSE-SU-2026:22974-1
SUSE-SU-2026:22975-1
SUSE-SU-2026:22980-1
SUSE-SU-2026:22981-1
SUSE-SU-2026:22982-1
SUSE-SU-2026:22983-1
SUSE-SU-2026:22984-1
SUSE-SU-2026:22985-1
SUSE-SU-2026:22986-1
SUSE-SU-2026:22987-1
SUSE-SU-2026:22988-1
SUSE-SU-2026:22989-1
SUSE-SU-2026:22990-1
SUSE-SU-2026:22991-1
SUSE-SU-2026:22992-1
SUSE-SU-2026:22993-1
SUSE-SU-2026:22995-1
SUSE-SU-2026:2799-1
SUSE-SU-2026:2800-1
SUSE-SU-2026:2839-1
SUSE-SU-2026:2840-1
SUSE-SU-2026:2841-1
SUSE-SU-2026:2914-1
SUSE-SU-2026:3044-1
SUSE-SU-2026:3089-1
SUSE-SU-2026:3130-1
SUSE-SU-2026:3156-1
SUSE-SU-2026:3166-1
SUSE-SU-2026:3246-1
SUSE-SU-2026:3248-1
SUSE-SU-2026:3254-1
SUSE-SU-2026:3256-1
SUSE-SU-2026:3264-1
SUSE-SU-2026:3286-1
SUSE-SU-2026:3289-1
SUSE-SU-2026:3301-1
SUSE-SU-2026:3316-1
SUSE-SU-2026:3319-1
SUSE-SU-2026:3321-1
SUSE-SU-2026:3343-1
SUSE-SU-2026:3344-1
SUSE-SU-2026:3345-1
SUSE-SU-2026:3350-1
SUSE-SU-2026:3351-1
SUSE-SU-2026:3354-1
SUSE-SU-2026:3369-1
SUSE-SU-2026:3372-1
SUSE-SU-2026:3376-1
SUSE-SU-2026:3383-1
SUSE-SU-2026:3388-1
SUSE-SU-2026:3393-1

Affected Products

Linux Kernel
Rocky Linux