{"api_version":"1","generated_at":"2026-07-24T20:58:32+00:00","cve":"CVE-2026-53372","urls":{"html":"https://cve.report/CVE-2026-53372","api":"https://cve.report/api/cve/CVE-2026-53372.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-53372","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-53372"},"summary":{"title":"iommu/vt-d: Block PASID attachment to nested domain with dirty tracking","description":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Block PASID attachment to nested domain with dirty tracking\n\nKernel lacks dirty tracking support on nested domain attached to PASID,\nfails the attachment early if nesting parent domain is dirty tracking\nconfigured, otherwise dirty pages would be lost.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-07-19 09:17:02","updated_at":"2026-07-19 09:17:02"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/9009c1af5458322469fa9a4371081a4449c5947d","name":"https://git.kernel.org/stable/c/9009c1af5458322469fa9a4371081a4449c5947d","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/cc5bd898ff70710ffc41cd8e5c2741cb64750047","name":"https://git.kernel.org/stable/c/cc5bd898ff70710ffc41cd8e5c2741cb64750047","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/3ea9ce757bd3de955b56e7bc5672fc479e40b045","name":"https://git.kernel.org/stable/c/3ea9ce757bd3de955b56e7bc5672fc479e40b045","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-53372","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53372","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 67f6f56b59126b3bf4fc6f4ea564e450fcfcf9f6 3ea9ce757bd3de955b56e7bc5672fc479e40b045 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 67f6f56b59126b3bf4fc6f4ea564e450fcfcf9f6 9009c1af5458322469fa9a4371081a4449c5947d git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 67f6f56b59126b3bf4fc6f4ea564e450fcfcf9f6 cc5bd898ff70710ffc41cd8e5c2741cb64750047 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.13","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.13 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.30 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.0.7 7.0.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"53372","cve":"CVE-2026-53372","epss":"0.001660000","percentile":"0.062360000","score_date":"2026-07-20","updated_at":"2026-07-21 00:13:14"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/iommu/intel/nested.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"3ea9ce757bd3de955b56e7bc5672fc479e40b045","status":"affected","version":"67f6f56b59126b3bf4fc6f4ea564e450fcfcf9f6","versionType":"git"},{"lessThan":"9009c1af5458322469fa9a4371081a4449c5947d","status":"affected","version":"67f6f56b59126b3bf4fc6f4ea564e450fcfcf9f6","versionType":"git"},{"lessThan":"cc5bd898ff70710ffc41cd8e5c2741cb64750047","status":"affected","version":"67f6f56b59126b3bf4fc6f4ea564e450fcfcf9f6","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/iommu/intel/nested.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.13"},{"lessThan":"6.13","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.30","versionType":"semver"},{"lessThanOrEqual":"7.0.*","status":"unaffected","version":"7.0.7","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.30","versionStartIncluding":"6.13","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.0.7","versionStartIncluding":"6.13","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1","versionStartIncluding":"6.13","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Block PASID attachment to nested domain with dirty tracking\n\nKernel lacks dirty tracking support on nested domain attached to PASID,\nfails the attachment early if nesting parent domain is dirty tracking\nconfigured, otherwise dirty pages would be lost."}],"providerMetadata":{"dateUpdated":"2026-07-19T09:10:32.453Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/3ea9ce757bd3de955b56e7bc5672fc479e40b045"},{"url":"https://git.kernel.org/stable/c/9009c1af5458322469fa9a4371081a4449c5947d"},{"url":"https://git.kernel.org/stable/c/cc5bd898ff70710ffc41cd8e5c2741cb64750047"}],"title":"iommu/vt-d: Block PASID attachment to nested domain with dirty tracking","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-53372","datePublished":"2026-07-19T09:10:32.453Z","dateReserved":"2026-06-09T07:44:35.401Z","dateUpdated":"2026-07-19T09:10:32.453Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-19 09:17:02","lastModifiedDate":"2026-07-19 09:17:02","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"53372","Ordinal":"1","Title":"iommu/vt-d: Block PASID attachment to nested domain with dirty t","CVE":"CVE-2026-53372","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"53372","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Block PASID attachment to nested domain with dirty tracking\n\nKernel lacks dirty tracking support on nested domain attached to PASID,\nfails the attachment early if nesting parent domain is dirty tracking\nconfigured, otherwise dirty pages would be lost.","Type":"Description","Title":"iommu/vt-d: Block PASID attachment to nested domain with dirty t"}]}}}