In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Block PASID attachment to nested domain with dirty tracking Kernel… (CVE-2026-53372)
A vulnerability in the Linux kernel's iommu/vt-d subsystem was resolved that involved improper handling of PASID attachment to nested domains with dirty tracking. The kernel lacked support for dirty tracking on nested domains attached to PASID, which could cause dirty pages to be lost if the nesting parent domain was configured for dirty tracking. This issue has been addressed by blocking PASID attachment in such cases.
AI Analysis
Technical Summary
The Linux kernel vulnerability CVE-2026-53372 concerns the iommu/vt-d component where the kernel failed to support dirty tracking on nested domains attached to PASID. Without this support, if the parent domain was configured for dirty tracking, the kernel would not properly track dirty pages, potentially leading to loss of dirty page information. The fix involves blocking PASID attachment to nested domains when the parent domain has dirty tracking enabled, preventing the issue.
Potential Impact
This vulnerability does not affect confidentiality or integrity but impacts availability, as indicated by the CVSS vector (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). The loss of dirty page tracking could lead to system instability or crashes related to memory management in affected kernel configurations.
Mitigation Recommendations
A fix for this vulnerability has been implemented in the Linux kernel by blocking PASID attachment to nested domains with dirty tracking enabled. Users should apply the official kernel updates that include this fix. Patch status is not explicitly confirmed in the provided data; therefore, check the vendor or Linux kernel advisories for the current remediation guidance.
In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Block PASID attachment to nested domain with dirty tracking Kernel… (CVE-2026-53372)
Description
A vulnerability in the Linux kernel's iommu/vt-d subsystem was resolved that involved improper handling of PASID attachment to nested domains with dirty tracking. The kernel lacked support for dirty tracking on nested domains attached to PASID, which could cause dirty pages to be lost if the nesting parent domain was configured for dirty tracking. This issue has been addressed by blocking PASID attachment in such cases.
CVSS v3.1
Score 5.5medium
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel vulnerability CVE-2026-53372 concerns the iommu/vt-d component where the kernel failed to support dirty tracking on nested domains attached to PASID. Without this support, if the parent domain was configured for dirty tracking, the kernel would not properly track dirty pages, potentially leading to loss of dirty page information. The fix involves blocking PASID attachment to nested domains when the parent domain has dirty tracking enabled, preventing the issue.
Potential Impact
This vulnerability does not affect confidentiality or integrity but impacts availability, as indicated by the CVSS vector (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). The loss of dirty page tracking could lead to system instability or crashes related to memory management in affected kernel configurations.
Mitigation Recommendations
A fix for this vulnerability has been implemented in the Linux kernel by blocking PASID attachment to nested domains with dirty tracking enabled. Users should apply the official kernel updates that include this fix. Patch status is not explicitly confirmed in the provided data; therefore, check the vendor or Linux kernel advisories for the current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-h5mw-rxh6-g2x3
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-53372"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- 3.1
Threat ID: 6a5d27af2a4a8d5989132b02
Added to database: 07/19/2026, 19:38:23 UTC
Last enriched: 07/30/2026, 12:02:32 UTC
Last updated: 09/03/2026, 22:52:12 UTC
Views: 90
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.