CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role
Published Jul 4, 2026
·Updated
In the Linux kernel, the following vulnerability has been resolved:
Other sources
KVM: x86: Fix shadow paging use-after-free due to unexpected role
— Microsoft
Affected Software
7 affected componentsFixes available
Linux Linux kernel=
Linux Linux kernel>=2.6.36<6.1.177
Linux Linux kernel>=6.2<6.6.144
Linux Linux kernel>=6.7<6.12.95
Linux Linux kernel>=6.13<6.18.38
Linux Linux kernel>=6.19<7.1.3
debian/linux<=6.1.176-1
6.1.187-16.12.107-17.2.6-17.2.7-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.187-1Fixed in 6.12.107-1Fixed in 7.2.6-1Fixed in 7.2.7-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch 0cb2af2ea66ad
Event History
Jul 4, 2026
CVE Published
via MITRE·11:51 AM
Data Sourced
via MITRE·11:51 AM
DescriptionSeverity
Data Sourced
via NVD·12:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·01:01 PM
DescriptionSeverityAffected Software
Jul 5, 2026
Data Sourced
via Microsoft·08:03 AM
DescriptionSeverityWeakness
Aug 13, 2026
Data Sourced
via Launchpad·08:40 PM
Description
Sep 24, 2026
Data Sourced
via Ubuntu·12:02 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·12:03 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-53359?
CVE-2026-53359 has a risk rating of 52.
2
How does CVE-2026-53359 affect the Linux kernel?
CVE-2026-53359 can lead to a use-after-free condition during shadow paging in the Linux kernel.
3
What software is impacted by CVE-2026-53359?
CVE-2026-53359 impacts the Linux kernel utilized within Microsoft Windows Server.
4
How do I mitigate CVE-2026-53359?
To mitigate CVE-2026-53359, ensure that your system is updated with the latest Linux kernel patches.
5
What kind of vulnerability is CVE-2026-53359 categorized as?
CVE-2026-53359 is categorized as a Use After Free vulnerability.