Junglewise Threat Intelligence

CVE-2026-53372: Linux Kernel data loss in Intel VT-d nested IOMMU domains

CVE-2026-53372 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's memory management system could lead to data loss during specific virtualization operations. When using nested virtual machine environments with Intel VT-d hardware, the system failed to track changes to memory pages correctly. This could result in 'dirty' pages being lost, potentially causing data corruption or system instability in virtualized workloads.

Technical details

A vulnerability in the Intel IOMMU (VT-d) driver's nested domain implementation allowed PASID attachments even when the parent domain had dirty tracking configured. Because the kernel lacks dirty tracking support for nested domains attached to a Process Address Space ID (PASID), this configuration would result in modified (dirty) pages not being tracked or saved. An attacker or a malfunctioning guest could trigger this state to cause silent data corruption or loss. The fix introduces a check in 'intel_nested_set_dev_pasid' to return an error if dirty operations are present on the domain.

Affected products

  • Linux Linux Kernel 6.13 through 6.18.29, 7.0.6

Timeline

  • 2026-07-19: disclosed
  • 2026-07-19: advisory

References

Related threats