CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role
In the Linux kernel, the following vulnerability has been resolved:
Other sources
KVM: x86: Fix shadow paging use-after-free due to unexpected role
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.180-1Fixed in 6.12.107-1Fixed in 7.1.12-1Fixed in 7.1.13-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch 0cb2af2ea66ad - Compensating control
To reduce exposure to the KVM shadow paging use-after-free, avoid workflows that (1) change a guest PDE mapping from outside the guest and (2) then delete/drop a KVM memslot before the fix from commit 0cb2af2ea66ad is applied.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53359?
CVE-2026-53359 has a risk rating of 52.
How does CVE-2026-53359 affect the Linux kernel?
CVE-2026-53359 can lead to a use-after-free condition during shadow paging in the Linux kernel.
What software is impacted by CVE-2026-53359?
CVE-2026-53359 impacts the Linux kernel utilized within Microsoft Windows Server.
How do I mitigate CVE-2026-53359?
To mitigate CVE-2026-53359, ensure that your system is updated with the latest Linux kernel patches.
What kind of vulnerability is CVE-2026-53359 categorized as?
CVE-2026-53359 is categorized as a Use After Free vulnerability.