Executive brief
A vulnerability has been identified in the Linux kernel's virtualization component (KVM) that could allow a local attacker to crash the system or potentially execute unauthorized code. The issue occurs when the system incorrectly manages memory mappings for virtual machines, leading to a 'use-after-free' condition where the kernel attempts to access memory that has already been released. This could impact the stability and security of servers hosting virtualized environments.
Technical details
A use-after-free vulnerability exists in the Linux kernel KVM x86 MMU subsystem. The root cause is a failure in `kvm_mmu_get_child_sp()` to compare the page role when reusing a shadow page. Specifically, when a Page Directory Entry (PDE) is modified to point to a non-leaf page, the system may reuse a `kvm_mmu_page` with a mismatched 'direct' role. This leads to incorrect GFN calculations during page zapping, causing `rmap_remove()` to fail to delete entries. When the associated memslot is later dropped, the shadow page is freed while the rmap entry persists, resulting in a use-after-free during subsequent GFN walks (e.g., dirty logging or MMU notifier invalidation). The vulnerability is fixed by ensuring the role is validated during child shadow page retrieval.
Affected products
- Linux Linux Kernel 2032a93d66fa to 1ae7d5a6db6c190ce183e3098ca0e0846e14d462
Timeline
- 2026-06-26: patched: Initial fix authored by Paolo Bonzini
- 2026-07-04: advisory: CVE-2026-53359 published
References
- https://git.kernel.org/stable/c/1ae7d5a6db6c190ce183e3098ca0e0846e14d462
- https://git.kernel.org/stable/c/2ad3afa40ac6aa340dada122f9abfa46c0a6eb35
- https://git.kernel.org/stable/c/5e470998a23e4c3d89ed24e8172cb22747e61efa
- https://git.kernel.org/stable/c/81ccda30b4e83d8f5cc4fd50503c44e3a33abfeb
- https://git.kernel.org/stable/c/9291654d69e08542de37755cebe4d5b02c3170d1
- https://git.kernel.org/stable/c/b1337aae5e194324e4810d561764e7793f8b3864