In the Linux kernel, the following vulnerability has been resolved: rust: arm64: set uwtable llvm module flag for CONFIG_UNWIND_TABLES Due to a… (CVE-2026-53346)
A vulnerability in the Linux kernel related to the Rust compiler's handling of unwind tables on arm64 architecture has been resolved. The issue stems from a rustc bug where the uwtable annotation is not set for the module, causing boot failures when certain kernel configurations are enabled. This leads to incorrect patching of constructor functions during boot, resulting in crashes. The fix involves setting the uwtable LLVM module flag conditionally based on the rustc version, with the upstream rustc fix expected in version 1.98.0.
AI Analysis
Technical Summary
The Linux kernel arm64 architecture was affected by a vulnerability due to a rustc compiler bug where the -Cforce-unwind-tables=y flag only annotated functions but not the module with the uwtable flag. This caused compiler-generated functions like 'asan.module_ctor' to lack the uwtable annotation. When CONFIG_UNWIND_PATCH_PAC_INTO_SCS is enabled, this results in incorrect DWARF information for KASAN constructors, causing the SCS boot patching code to patch instructions inconsistently (patching paciasp but not autiasp). This mismatch leads to boot-time crashes. The issue is tracked as CVE-2026-53346 and is addressed by adding a version check to apply the flag only on affected rustc versions. The rustc fix is included starting with version 1.98.0, expected in August 2026.
Potential Impact
The vulnerability causes boot failures and kernel crashes on affected arm64 systems when CONFIG_UNWIND_PATCH_PAC_INTO_SCS is enabled. Specifically, it triggers a KASAN global out-of-bounds read leading to a crash during kernel initialization. This impacts system availability and stability on affected configurations.
Mitigation Recommendations
A fix is available upstream in the rustc compiler starting with version 1.98.0 (expected release August 20, 2026). The Linux kernel applies a conditional flag based on rustc version to mitigate the issue. Users should update to rustc 1.98.0 or later once released and ensure their kernel is patched accordingly. Patch status for the Linux kernel itself is not explicitly stated; check vendor advisories for kernel updates incorporating this fix. No workaround is indicated prior to rustc update.
In the Linux kernel, the following vulnerability has been resolved: rust: arm64: set uwtable llvm module flag for CONFIG_UNWIND_TABLES Due to a… (CVE-2026-53346)
Description
A vulnerability in the Linux kernel related to the Rust compiler's handling of unwind tables on arm64 architecture has been resolved. The issue stems from a rustc bug where the uwtable annotation is not set for the module, causing boot failures when certain kernel configurations are enabled. This leads to incorrect patching of constructor functions during boot, resulting in crashes. The fix involves setting the uwtable LLVM module flag conditionally based on the rustc version, with the upstream rustc fix expected in version 1.98.0.
CVSS v3.1
Score 7.1high
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel arm64 architecture was affected by a vulnerability due to a rustc compiler bug where the -Cforce-unwind-tables=y flag only annotated functions but not the module with the uwtable flag. This caused compiler-generated functions like 'asan.module_ctor' to lack the uwtable annotation. When CONFIG_UNWIND_PATCH_PAC_INTO_SCS is enabled, this results in incorrect DWARF information for KASAN constructors, causing the SCS boot patching code to patch instructions inconsistently (patching paciasp but not autiasp). This mismatch leads to boot-time crashes. The issue is tracked as CVE-2026-53346 and is addressed by adding a version check to apply the flag only on affected rustc versions. The rustc fix is included starting with version 1.98.0, expected in August 2026.
Potential Impact
The vulnerability causes boot failures and kernel crashes on affected arm64 systems when CONFIG_UNWIND_PATCH_PAC_INTO_SCS is enabled. Specifically, it triggers a KASAN global out-of-bounds read leading to a crash during kernel initialization. This impacts system availability and stability on affected configurations.
Mitigation Recommendations
A fix is available upstream in the rustc compiler starting with version 1.98.0 (expected release August 20, 2026). The Linux kernel applies a conditional flag based on rustc version to mitigate the issue. Users should update to rustc 1.98.0 or later once released and ensure their kernel is patched accordingly. Patch status for the Linux kernel itself is not explicitly stated; check vendor advisories for kernel updates incorporating this fix. No workaround is indicated prior to rustc update.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-mp8j-7v82-r69x
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-53346"]
- Ecosystems
- []
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a6150e79c2644c7f8da2060
Added to database: 07/22/2026, 23:23:19 UTC
Last enriched: 07/22/2026, 23:38:17 UTC
Last updated: 07/31/2026, 19:24:49 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.