Improper Check or Handling of Exceptional Conditions in Linux kernel - CVE-2026-53345
Published: July 11, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of a warning condition in KVM memory dirty page tracking in virt/kvm/kvm_main.c when destroying a vCPU after certain SEV-ES VM-Exits without a subsequent KVM_RUN. A local user can trigger this condition to cause a denial of service.
The issue occurs in SEV-ES guest scenarios where KVM retains a writable mapping of a guest page across an exit to userspace.
Affected software
Ubuntu
linux (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
How to mitigate CVE-2026-53345
linux (Ubuntu package) - addressed in versions 7.0.0-31.31, 7.0.0-31.31.1, 7.0.0-31.31~24.04.1, 7.0.0-1006.7, 7.0.0-1011.11~24.04.1, 7.0.0-1012.12, 7.0.0-1012.12~24.04.1
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1013.13
External References
- https://git.kernel.org/stable/c/033d39e41fc30f484f4e4f37fb4cd76b12cbb18e
- https://git.kernel.org/stable/c/343e95c8ecc40e0738975ef4ee24c0c35e800e6b
- https://git.kernel.org/stable/c/66a8e7ddd901023c89a2733494d827eca3f9c1b0
- https://git.kernel.org/stable/c/8618004d3e897c0f1b71d9a9ab860461289bb89a
- https://git.kernel.org/stable/c/99d7d43784ae3235026581e9bf892c036e04c8e6