Skip to content
VulniPulse
Advisory severityHigh7.8Red Hat Linux

High [CVE-2026-53359] Fix shadow paging use-after-free due to unexpected role

This high-severity Red Hat Linux advisory covers CVE-2026-53359 affecting Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-53359 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Red Hat LinuxLinux Kernel
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free due to unexpected GFN") fixed a shadow paging mismatch between stored and computed GFNs; the bug could be triggered by changing a PDE mapping from outside the guest, and then deleting a memslot.

The rmap_remove() call would miss entries created after the PDE change because the GFN of the leaf SPTE does not match the GFN of the struct kvm_mmu_page. A similar hole however remains if the modified PDE points to a non-leaf page.

In this case the gfn can be made to match, but the role does not match: the original large 2MB page creates a kvm_mmu_page with direct=1, while the new 4KB needs a kvm_mmu_page with direct=0. However, kvm_mmu_get_child_sp() does not compare the role, and therefore reuses the page.

The next step is installing a leaf (4KB) SPTE on the new path which records an rmap entry under the gfn resolved by the walk. But when that child is zapped its parent kvm_mmu_page has direct=1 and kvm_mmu_page_get_gfn() computes the gfn for the 4KB page as sp->gfn + index instead of using sp->shadowed_translation[] (or sp->gfns[] in older kernels).

It therefore fails to remove the recorded entry.

Affected versions

No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.

Official advisory · high-confidence parse· fetched 15 days ago·verify at source

Fixed versions
  • kernel-0:6.12.0-211.32.1.el10_2
  • kpatch-patch
  • kernel-0:6.12.0-55.88.1.el10_0
  • kernel-rt-0:4.18.0-553.143.1.rt7.484.el8_10
  • kernel-0:4.18.0-553.143.1.el8_10
  • kernel-0:4.18.0-372.204.1.el8_6
  • kernel-0:4.18.0-477.154.1.el8_8
  • kernel-0:5.14.0-687.24.1.el9_8
  • kernel-0:5.14.0-284.181.1.el9_2
  • kernel-rt-0:5.14.0-284.181.1.rt14.466.el9_2
  • kernel-0:5.14.0-427.137.1.el9_4
  • kernel-0:5.14.0-570.127.1.el9_6
  • rhcos-412.86.202608080425-0
  • rhcos-413.92.202608111330-0
  • rhcos-414.92.202607210313-0
  • rhcos-418.94.202607211754-0
  • rhcos-4.19.9.6.202607220857-0
  • rhcos-4.20.9.6.202607151937-0
  • rhcos-4.21.9.6.202607151836-0
  • rhcos-4.22.9.8.202607152026-0
  • RHSA-2026:36956
  • RHSA-2026:43826
  • RHSA-2026:39371
  • RHSA-2026:39082
  • RHSA-2026:39083
  • RHSA-2026:44004
  • RHSA-2026:49033
  • RHSA-2026:41229
  • RHSA-2026:43847
  • RHSA-2026:36957
  • RHSA-2026:43825
  • RHSA-2026:40082
  • RHSA-2026:39983
  • RHSA-2026:44003
  • RHSA-2026:37729
  • RHSA-2026:44006
  • RHSA-2026:38902
  • RHSA-2026:44007
  • RHSA-2026:54205
  • RHSA-2026:54187

Official advisory · high-confidence parse· fetched 15 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • This vulnerability can be mitigated by disabling nested virtualization. Create a file in `/etc/modprobe.d/` with a descriptive name, such as `cve-2026-53359-mitigation.conf`. In that file, disable nested virtualization for the `kvm_intel` and `kvm_amd` kernel modules: ``` options kvm-intel nested=0 options kvm-amd nested=0 ``` Use `lsmod` to determine if either module is already loaded. If so, remove loaded modules with `modprobe -r`. To validate that nested virtualization is disabled, read the files `/sys/module/kvm_intel/parameters/nested` and `/sys/module/kvm_amd/parameters/nested`. If these modules are loaded, those files should read `N` to indicate that the feature is disabled. In OpenShift 4, a MachineConfig can be utilized to create a modprobe configuration allowing control of the module on applicable nodes. See the following article for an example. https://access.redhat.com/solutions/6979679 Red Hat OpenStack Platform 16.2 and 17.1, and Red Hat OpenStack Services on OpenShift 18.0, can be affected when their nodes run a vulnerable RHEL or OpenShift kernel. Follow the knowledge base article to apply the mitigation. https://access.redhat.com/solutions/7145295

Official advisory · high-confidence parse· fetched 15 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.