In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption Commit… (CVE-2026-53281)
A vulnerability in the Linux kernel's iommu/vt-d component could lead to a NULL pointer dereference or refcount corruption. This occurs when a device PASID is not found, causing teardown operations to execute unconditionally on a NULL pointer, potentially resulting in use-after-free conditions for devices sharing the domain. The issue has been fixed by adding an early return if the device PASID is NULL before teardown. Red Hat has released security updates for Red Hat Enterprise Linux 9 and 10 to address this vulnerability. Systems must be rebooted after applying the update.
AI Analysis
Technical Summary
The Linux kernel vulnerability (CVE-2026-53281) involves the iommu/vt-d subsystem where a NULL pointer dereference or refcount corruption can occur if a device PASID is not found in the dev_pasids list. The teardown operations were executed unconditionally, leading to dereferencing a NULL pointer or unbalanced reference counts, which could cause premature refcount drops and use-after-free scenarios for devices sharing the domain. The fix involves returning early if dev_pasid is NULL to prevent these unsafe operations. Red Hat has issued patches for this vulnerability in their Enterprise Linux 9 and 10 kernel packages.
Potential Impact
Successful exploitation could cause a NULL pointer dereference or refcount corruption in the Linux kernel's iommu/vt-d code, potentially leading to use-after-free conditions affecting devices sharing the domain. This can result in system instability, crashes, or escalation of privileges due to kernel memory corruption. The vulnerability has a CVSS 3.1 base score of 9.8 (AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H), indicating high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Red Hat has released official kernel updates for Red Hat Enterprise Linux versions 9 and 10 that address this vulnerability. Users should apply these updates promptly and reboot affected systems to ensure the fix takes effect. Refer to Red Hat advisory RHSA-2026:47017 for RHEL 10 and RHSA-2026:47040 for RHEL 9 for detailed update instructions. No additional mitigations are required beyond applying the official patches and rebooting.
In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption Commit… (CVE-2026-53281)
Description
A vulnerability in the Linux kernel's iommu/vt-d component could lead to a NULL pointer dereference or refcount corruption. This occurs when a device PASID is not found, causing teardown operations to execute unconditionally on a NULL pointer, potentially resulting in use-after-free conditions for devices sharing the domain. The issue has been fixed by adding an early return if the device PASID is NULL before teardown. Red Hat has released security updates for Red Hat Enterprise Linux 9 and 10 to address this vulnerability. Systems must be rebooted after applying the update.
CVSS v3.1
Score 8.8high
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel vulnerability (CVE-2026-53281) involves the iommu/vt-d subsystem where a NULL pointer dereference or refcount corruption can occur if a device PASID is not found in the dev_pasids list. The teardown operations were executed unconditionally, leading to dereferencing a NULL pointer or unbalanced reference counts, which could cause premature refcount drops and use-after-free scenarios for devices sharing the domain. The fix involves returning early if dev_pasid is NULL to prevent these unsafe operations. Red Hat has issued patches for this vulnerability in their Enterprise Linux 9 and 10 kernel packages.
Potential Impact
Successful exploitation could cause a NULL pointer dereference or refcount corruption in the Linux kernel's iommu/vt-d code, potentially leading to use-after-free conditions affecting devices sharing the domain. This can result in system instability, crashes, or escalation of privileges due to kernel memory corruption. The vulnerability has a CVSS 3.1 base score of 9.8 (AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H), indicating high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Red Hat has released official kernel updates for Red Hat Enterprise Linux versions 9 and 10 that address this vulnerability. Users should apply these updates promptly and reboot affected systems to ensure the fix takes effect. Refer to Red Hat advisory RHSA-2026:47017 for RHEL 10 and RHSA-2026:47040 for RHEL 9 for detailed update instructions. No additional mitigations are required beyond applying the official patches and rebooting.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-p9cf-q2gf-35mq
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-53281"]
- Ecosystems
- []
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a6ae5599c2644c7f89a933d
Added to database: 07/30/2026, 05:47:05 UTC
Last enriched: 07/30/2026, 07:26:50 UTC
Last updated: 07/31/2026, 19:24:48 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.