iommu/vt-d: Block PASID attachment to nested domain with dirty tracking
Summary
| CVE | CVE-2026-53372 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-19 09:17:02 UTC |
| Updated | 2026-07-19 09:17:02 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Block PASID attachment to nested domain with dirty tracking Kernel lacks dirty tracking support on nested domain attached to PASID, fails the attachment early if nesting parent domain is dirty tracking configured, otherwise dirty pages would be lost. |
Risk And Classification
EPSS: 0.001660000 probability, percentile 0.062360000 (date 2026-07-20)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 67f6f56b59126b3bf4fc6f4ea564e450fcfcf9f6 3ea9ce757bd3de955b56e7bc5672fc479e40b045 git | Not specified |
| CNA | Linux | Linux | affected 67f6f56b59126b3bf4fc6f4ea564e450fcfcf9f6 9009c1af5458322469fa9a4371081a4449c5947d git | Not specified |
| CNA | Linux | Linux | affected 67f6f56b59126b3bf4fc6f4ea564e450fcfcf9f6 cc5bd898ff70710ffc41cd8e5c2741cb64750047 git | Not specified |
| CNA | Linux | Linux | affected 6.13 | Not specified |
| CNA | Linux | Linux | unaffected 6.13 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.30 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.0.7 7.0.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/9009c1af5458322469fa9a4371081a4449c5947d | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/cc5bd898ff70710ffc41cd8e5c2741cb64750047 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/3ea9ce757bd3de955b56e7bc5672fc479e40b045 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.