CVE-2026-53359
published 2026-07-04CVE-2026-53359: In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad…
PriorityP349high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.91%
56.3th percentile
In the Linux kernel, the following vulnerability has been resolved:
KVM: x86: Fix shadow paging use-after-free due to unexpected role
Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free due
to unexpected GFN") fixed a shadow paging mismatch between stored and
computed GFNs; the bug could be triggered by changing a PDE mapping from
outside the guest, and then deleting a memslot. The rmap_remove()
call would miss entries created after the PDE change because the GFN
of the leaf SPTE does not match the GFN of the struct kvm_mmu_page.
A similar hole however remains if the modified PDE points to a non-leaf
page. In this case the gfn can be made to match, but the role does not
match: the original large 2MB page creates a kvm_mmu_page with direct=1,
while the new 4KB needs a kvm_mmu_page with direct=0. However,
kvm_mmu_get_child_sp() does not compare the role, and therefore reuses
the page.
The next step is installing a leaf (4KB) SPTE on the new path which
records an rmap entry under the gfn resolved by the walk. But when
that child is zapped its parent kvm_mmu_page has direct=1 and
kvm_mmu_page_get_gfn() computes the gfn for the 4KB page as
sp->gfn + index instead of using sp->shadowed_translation[] (or sp->gfns[]
in older kernels). It therefore fails to remove the recorded entry.
When the memslot is dropped the shadow page is freed but the rmap
entry survives, as in the scenario that was already fixed. Code that
later walks that gfn (dirty logging, MMU notifier invalidation, and
so on) dereferences an sptep that lies in the freed page, causing the
use-after-free.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= 2032a93d66fa282ba0f2ea9152eeff9511fa9a96 < b1337aae5e194324e4810d561764e7793f8b3864 | b1337aae5e194324e4810d561764e7793f8b3864 |
| linux | linux | >= 2032a93d66fa282ba0f2ea9152eeff9511fa9a96 < 9291654d69e08542de37755cebe4d5b02c3170d1 | 9291654d69e08542de37755cebe4d5b02c3170d1 |
| linux | linux | >= 2032a93d66fa282ba0f2ea9152eeff9511fa9a96 < 2ad3afa40ac6aa340dada122f9abfa46c0a6eb35 | 2ad3afa40ac6aa340dada122f9abfa46c0a6eb35 |
| linux | linux | >= 2032a93d66fa282ba0f2ea9152eeff9511fa9a96 < 5e470998a23e4c3d89ed24e8172cb22747e61efa | 5e470998a23e4c3d89ed24e8172cb22747e61efa |
| linux | linux | >= 2032a93d66fa282ba0f2ea9152eeff9511fa9a96 < 1ae7d5a6db6c190ce183e3098ca0e0846e14d462 | 1ae7d5a6db6c190ce183e3098ca0e0846e14d462 |
| linux | linux | >= 2032a93d66fa282ba0f2ea9152eeff9511fa9a96 < 81ccda30b4e83d8f5cc4fd50503c44e3a33abfeb | 81ccda30b4e83d8f5cc4fd50503c44e3a33abfeb |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 2.6.36 < 6.1.177 | 6.1.177 |
| linux | linux_kernel | >= 6.13 < 6.18.38 | 6.18.38 |
| linux | linux_kernel | >= 6.19 < 7.1.3 | 7.1.3 |
| linux | linux_kernel | >= 6.2 < 6.6.144 | 6.6.144 |
| linux | linux_kernel | >= 6.7 < 6.12.95 | 6.12.95 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 7.1.2 KVM rmap_remove shadowed_translation[] use after free (EUVD-2026-41666)
vuldb·2026-07-04
CVE-2026-53359 [CRITICAL] Linux Kernel up to 7.1.2 KVM rmap_remove shadowed_translation[] use after free (EUVD-2026-41666)
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.1.176/6.6.143/6.12.94/6.18.37/7.1.2. Affected by this issue is the function rmap_remove of the component KVM. Such manipulation of the argument shadowed_translation[] leads to use after free.
This vulnerability is uniquely identified as CVE-2026-53359. The attack can only be initiated within the local network. No exploit exists.
You should upgrade the affected component.
GHSA
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-fre
ghsa_unreviewed·2026-07-04
CVE-2026-53359 In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-fre
In the Linux kernel, the following vulnerability has been resolved:
KVM: x86: Fix shadow paging use-after-free due to unexpected role
Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free due
to unexpected GFN") fixed a shadow paging mismatch between stored and
computed GFNs; the bug could be triggered by changing a PDE mapping from
outside the guest, and then deleting a memslot. The rmap_remove()
call would miss entries created after the PDE change because the GFN
of the leaf SPTE does not match the GFN of the struct kvm_mmu_page.
A similar hole however remains if the modified PDE points to a non-leaf
page. In this case the gfn can be made to match, but the role does not
match: the original large 2MB page creates a kvm_mmu_page with direct=1,
while the new 4KB needs a kvm_m
Red Hat
kernel: KVM: x86: Fix shadow paging use-after-free due to unexpected role
vendor_redhat·2026-07-04·CVSS 7.0
CVE-2026-53359 [HIGH] CWE-825 kernel: KVM: x86: Fix shadow paging use-after-free due to unexpected role
kernel: KVM: x86: Fix shadow paging use-after-free due to unexpected role
In the Linux kernel, the following vulnerability has been resolved:
KVM: x86: Fix shadow paging use-after-free due to unexpected role
Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free due
to unexpected GFN") fixed a shadow paging mismatch between stored and
computed GFNs; the bug could be triggered by changing a PDE mapping from
outside the guest, and then deleting a memslot. The rmap_remove()
call would miss entries created after the PDE change because the GFN
of the leaf SPTE does not match the GFN of the struct kvm_mmu_page.
A similar hole however remains if the modified PDE points to a non-leaf
page. In this case the gfn can be made to match, but the role does not
match: the original large 2MB pa
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
blogs_hackernews·2026-07-13
CVE-2026-50746 ⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
Somewhere right now, a security tool is quietly finding bugs faster than any human can fix them. That's supposed to be the good news. The catch is that the attackers have the same tools, pointed the other way, and they don't file tickets.
That's the shape of this week. Trusted code turns on the people who installed it. Old bugs from last year are still landing because the fix sat in a queue too long. Fake installers, poisoned packages, systems left facing the open internet, and helpful little AI assistants running instructions that were
Checkpoint
13th July – Threat Intelligence Report
blogs_checkpoint·2026-07-13
CVE-2025-3248 13th July – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 13th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 13th July, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
U.S. auto insurer AssuranceAmerica has disclosed a data breach affecting approximately 7 million people. Attackers targeted an employee and used compromised credentials to access company systems, stealing names, contact information, driver’s license numbers, insurance policy and account data, vehicle information, and claims deta
Hackernews
16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems
blogs_hackernews·2026-07-06
CVE-2026-53359 16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## 16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems
A use-after-free bug in Linux's KVM hypervisor can be triggered from a guest virtual machine to corrupt the shadow-page state of the host kernel that runs it.
Dubbed ' Januscape ' and tracked as CVE-2026-53359 , the flaw sits in the shadow MMU code that KVM shares across both Intel and AMD. The public proof-of-concept panics the host; the researcher claims that a separate, unreleased exploit turns the same bug into full host code execution.
Security researcher Hyunwoo Kim (@v4bel) found and reported the bug. He described Januscape as the f
Bugzilla
CVE-2026-53359 kernel: KVM: x86: Fix shadow paging use-after-free due to unexpected role
bugzilla·2026-07-04
CVE-2026-53359 [HIGH] CVE-2026-53359 kernel: KVM: x86: Fix shadow paging use-after-free due to unexpected role
CVE-2026-53359 kernel: KVM: x86: Fix shadow paging use-after-free due to unexpected role
In the Linux kernel, the following vulnerability has been resolved:
KVM: x86: Fix shadow paging use-after-free due to unexpected role
Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free due
to unexpected GFN") fixed a shadow paging mismatch between stored and
computed GFNs; the bug could be triggered by changing a PDE mapping from
outside the guest, and then deleting a memslot. The rmap_remove()
call would miss entries created after the PDE change because the GFN
of the leaf SPTE does not match the GFN of the struct kvm_mmu_page.
A similar hole however remains if the modified PDE points to a non-leaf
page. In this case the gfn can be made to match, but the role does not
match: the ori
https://git.kernel.org/stable/c/1ae7d5a6db6c190ce183e3098ca0e0846e14d462https://git.kernel.org/stable/c/2ad3afa40ac6aa340dada122f9abfa46c0a6eb35https://git.kernel.org/stable/c/5e470998a23e4c3d89ed24e8172cb22747e61efahttps://git.kernel.org/stable/c/81ccda30b4e83d8f5cc4fd50503c44e3a33abfebhttps://git.kernel.org/stable/c/9291654d69e08542de37755cebe4d5b02c3170d1https://git.kernel.org/stable/c/b1337aae5e194324e4810d561764e7793f8b3864http://www.openwall.com/lists/oss-security/2026/07/06/7https://github.com/V4bel/Januscape/blob/main/assets/write-up.md
2026-07-04
Published