Junglewise Threat Intelligence

CVE-2026-53359: Linux Kernel KVM shadow paging use-after-free in x86 MMU

CVE-2026-53359 · Severity: high · CVSS 7.8 · Published 2026-07-04

Technologies: Google Cloud Platform, Linux Kernel. Vendors: Google, Linux.

Executive brief

A vulnerability has been identified in the Linux kernel's virtualization component (KVM) that could allow a local attacker to crash the system or potentially execute unauthorized code. The issue occurs when the system incorrectly manages memory mappings for virtual machines, leading to a 'use-after-free' condition where the kernel attempts to access memory that has already been released. This could impact the stability and security of servers hosting virtualized environments.

Technical details

A use-after-free vulnerability exists in the Linux kernel KVM x86 MMU subsystem. The root cause is a failure in `kvm_mmu_get_child_sp()` to compare the page role when reusing a shadow page. Specifically, when a Page Directory Entry (PDE) is modified to point to a non-leaf page, the system may reuse a `kvm_mmu_page` with a mismatched 'direct' role. This leads to incorrect GFN calculations during page zapping, causing `rmap_remove()` to fail to delete entries. When the associated memslot is later dropped, the shadow page is freed while the rmap entry persists, resulting in a use-after-free during subsequent GFN walks (e.g., dirty logging or MMU notifier invalidation). The vulnerability is fixed by ensuring the role is validated during child shadow page retrieval.

Affected products

  • Linux Linux Kernel 2032a93d66fa to 1ae7d5a6db6c190ce183e3098ca0e0846e14d462

Timeline

  • 2026-06-26: patched: Initial fix authored by Paolo Bonzini
  • 2026-07-04: advisory: CVE-2026-53359 published

References

Related threats