CVE-2026-53359
CVE-2026-53359: 2 tracked advisory records across NetApp, Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
NetApp
1 advisory- Advisory severityHigh7.8
High [CVE-2026-53359] Linux Kernel Vulnerability in NetApp Products
NTAP-20260710-0017Source published Source updated
Linux kernel versions 2.6.36-rc1 through 6.1.176, 6.13-rc1 through 6.18.37, 6.19-rc1 through 7.1.2, 6.2-rc1 through 6.6.143 and 6.7-rc1 through 6.12.94 are susceptible to a vulnerability referred to as Januscape which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: NetApp HCI Baseboard Management Controller (BMC) - H610S. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
- Affected products in this advisory
- NetApp HCI Baseboard Management Controller (BMC) - H610S
- Source-reported affected versions
- 2.6.36
- 6.1.176
- 6.13
- 6.18.37
4 more entries in the full advisory.
- Source-reported fixed versions
- No fixed-version detail extracted. This does not mean no fix exists.
- Mitigation guidance
- NetApp HCI Baseboard Management Controller (BMC) - H610S has no planned fix; migrate to a supported release or product and consult NetApp's end-of-support notice.
Red Hat
1 advisory- Advisory severityHigh7.8
High [CVE-2026-53359] Fix shadow paging use-after-free due to unexpected role
CVE-2026-53359Source published Source updated
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free due to unexpected GFN") fixed a shadow paging mismatch between stored and computed GFNs; the bug could be triggered by changing a PDE mapping from outside the guest, and then deleting a memslot. The rmap_remove() call would miss entries created after the PDE change because the GFN of the leaf SPTE does not match the GFN of the struct kvm_mmu_page. A similar hole however remains if the modified PDE points to a non-leaf page. In this case the gfn can be made to match, but the role does not match: the original large 2MB page creates a kvm_mmu_page with direct=1, while the new 4KB needs a…
- Affected products in this advisory
- Red Hat Enterprise Linux 10.0 Extended Update Support
- Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
- Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
- Red Hat Enterprise Linux 8.8 Telecommunications Update Service
14 more entries in the full advisory.
- Source-reported affected versions
- Affected-version details not available in this record.
- Source-reported fixed versions
- kernel-0:6.12.0-211.32.1.el10_2
- kpatch-patch
- kernel-0:6.12.0-55.88.1.el10_0
- kernel-rt-0:4.18.0-553.143.1.rt7.484.el8_10
36 more entries in the full advisory.
- Mitigation guidance
- This vulnerability can be mitigated by disabling nested virtualization. Create a file in `/etc/modprobe.d/` with a descriptive name, such as `cve-2026-53359-mitigation.conf`. In that file, disable nested virtualization for the `kvm_intel` and `kvm_amd` kernel modules: ``` options kvm-intel nested=0 options kvm-amd nested=0 ``` Use `lsmod` to determine if either module is already loaded. If so, remove loaded modules with `modprobe -r`. To validate that nested virtualization is disabled, read the files `/sys/module/kvm_intel/parameters/nested` and `/sys/module/kvm_amd/parameters/nested`. If these modules are loaded, those files should read `N` to indicate that the feature is disabled. In OpenShift 4, a MachineConfig can be utilized to create a modprobe configuration allowing control of the module on applicable nodes. See the following article for an example. https://access.redhat.com/solutions/6979679 Red Hat OpenStack Platform 16.2 and 17.1, and Red Hat OpenStack Services on OpenShift 18.0, can be affected when their nodes run a vulnerable RHEL or OpenShift kernel. Follow the knowledge base article to apply the mitigation. https://access.redhat.com/solutions/7145295
Android app · Google Play
Turn CVE research into alerts on your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.