目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-53359— Linux kernel 安全漏洞

一分钟漏洞结论

影响对象
Linux Linux
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Linux kernel是美国Linux基金会开源的一款操作系统内核。 Linux kernel 2.6.36版本存在安全漏洞,该漏洞源于KVM x86影子分页中未预期角色导致的释放后重用问题,可能导致在释放页面后仍引用rmap条目,从而引发释放后重用。

CVSS 8.8 · High EPSS 0.17% · P6

影响版本矩阵 16

厂商产品 版本范围状态
Linux Linux 2032a93d66fa282ba0f2ea9152eeff9511fa9a96< 0b5e8ead71e683bcf6232db16234cf7e6d553a23 affected
2032a93d66fa282ba0f2ea9152eeff9511fa9a96< b1337aae5e194324e4810d561764e7793f8b3864 affected
2032a93d66fa282ba0f2ea9152eeff9511fa9a96< 9291654d69e08542de37755cebe4d5b02c3170d1 affected
2032a93d66fa282ba0f2ea9152eeff9511fa9a96< 2ad3afa40ac6aa340dada122f9abfa46c0a6eb35 affected
2032a93d66fa282ba0f2ea9152eeff9511fa9a96< 5e470998a23e4c3d89ed24e8172cb22747e61efa affected
2032a93d66fa282ba0f2ea9152eeff9511fa9a96< 1ae7d5a6db6c190ce183e3098ca0e0846e14d462 affected
2032a93d66fa282ba0f2ea9152eeff9511fa9a96< 81ccda30b4e83d8f5cc4fd50503c44e3a33abfeb affected
2.6.36 affected
… +8 条更多
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-53359 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
KVM: x86: Fix shadow paging use-after-free due to unexpected role
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free due to unexpected GFN") fixed a shadow paging mismatch between stored and computed GFNs; the bug could be triggered by changing a PDE mapping from outside the guest, and then deleting a memslot. The rmap_remove() call would miss entries created after the PDE change because the GFN of the leaf SPTE does not match the GFN of the struct kvm_mmu_page. A similar hole however remains if the modified PDE points to a non-leaf page. In this case the gfn can be made to match, but the role does not match: the original large 2MB page creates a kvm_mmu_page with direct=1, while the new 4KB needs a kvm_mmu_page with direct=0. However, kvm_mmu_get_child_sp() does not compare the role, and therefore reuses the page. The next step is installing a leaf (4KB) SPTE on the new path which records an rmap entry under the gfn resolved by the walk. But when that child is zapped its parent kvm_mmu_page has direct=1 and kvm_mmu_page_get_gfn() computes the gfn for the 4KB page as sp->gfn + index instead of using sp->shadowed_translation[] (or sp->gfns[] in older kernels). It therefore fails to remove the recorded entry. When the memslot is dropped the shadow page is freed but the rmap entry survives, as in the scenario that was already fixed. Code that later walks that gfn (dirty logging, MMU notifier invalidation, and so on) dereferences an sptep that lies in the freed page, causing the use-after-free.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会开源的一款操作系统内核。 Linux kernel 2.6.36版本存在安全漏洞,该漏洞源于KVM x86影子分页中未预期角色导致的释放后重用问题,可能导致在释放页面后仍引用rmap条目,从而引发释放后重用。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
Linux Linux 2032a93d66fa282ba0f2ea9152eeff9511fa9a96 ~ 0b5e8ead71e683bcf6232db16234cf7e6d553a23 -
Linux Linux 2.6.36 -

二、漏洞 CVE-2026-53359 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-53359 的情报信息

请登录查看更多情报信息。

CVE-2026-53359 补丁与修复 (7)

同批安全公告 · Linux · 2026-07-04 · 共 4 条

CVE-2026-53360 8.8 HIGH Linux kernel 安全漏洞
CVE-2026-53362 7.8 HIGH Linux kernel 安全漏洞
CVE-2026-53361 7.1 HIGH Linux kernel 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-53359

暂无评论


发表评论