CVE-2026-53277 is a vulnerability in Linux Kernel
Published on June 25, 2026
KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation
In the Linux kernel, the following vulnerability has been resolved:
KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation
walk_s1() and kvm_walk_nested_s2() expect to be called while holding
kvm->srcu to guard against memslot changes. While this is generally
the case, __kvm_at_s12() and __kvm_find_s1_desc_level() call into the
respective walkers without taking kvm->srcu.
Fix by acquiring kvm->srcu prior to the table walk in both instances.
Products Associated with CVE-2026-53277
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version be04cebf3e78874627dc1042991d5d504464a5cc and below 97706097f9b851cfe55c3b00b083dfc2bcf542bc is affected.
- Version be04cebf3e78874627dc1042991d5d504464a5cc and below ec42b4ed1b072ea2d03f086061aa67bad6d8de39 is affected.
- Version be04cebf3e78874627dc1042991d5d504464a5cc and below f2ca45b50d4216c9cc7ffabf50d9ad1932209251 is affected.
- Version 6.12 is affected.
- Before 6.12 is unaffected.
- Version 6.18.36, <= 6.18.* is unaffected.
- Version 7.0.13, <= 7.0.* is unaffected.
- Version 7.1, <= * is unaffected.