CVE-2026-53343
Gravedad CVSS v3.1:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
01/07/2026
Última modificación:
23/07/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ARM: 9475/1: entry: use byte load for KASAN VMAP stack shadow<br />
<br />
Commit 44e9a3bb76e5 ("ARM: 9430/1: entry: Do a dummy read from<br />
VMAP shadow") added a dummy read from the KASAN VMAP stack shadow in<br />
__switch_to(). The read uses ldr, but the KASAN shadow address is<br />
byte-granular and is not guaranteed to be word aligned.<br />
<br />
ARMv5 faults unaligned word loads. With CONFIG_KASAN_VMALLOC and<br />
CONFIG_VMAP_STACK enabled, ARM926/VersatilePB crashes in __switch_to()<br />
with an alignment exception before reaching init.<br />
<br />
Use ldrb for the dummy shadow access. The code only needs to fault in the<br />
shadow mapping if the stack shadow is missing, so a byte load is sufficient<br />
and matches the granularity of KASAN shadow memory.
Impacto
Puntuación base 3.x
5.50
Gravedad 3.x
MEDIA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.1.120 (incluyendo) | 6.1.176 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.6.64 (incluyendo) | 6.6.143 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.12.4 (incluyendo) | 6.12.94 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (incluyendo) | 6.18.36 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (incluyendo) | 7.0.13 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc7:*:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/2a4dc9a0ac3326e79fb58fdaae724b92127709a9
- https://git.kernel.org/stable/c/517720913bd3c17a52cd55a740064f68455ab88e
- https://git.kernel.org/stable/c/77a1f6883dc6e837bb2cb30b9b02e2f94338e2c6
- https://git.kernel.org/stable/c/c0b8c148a7754826156993ed6442d31536ec86b4
- https://git.kernel.org/stable/c/c2e3aadc8fef7da068490597fc5582f8f362aeb2
- https://git.kernel.org/stable/c/c74990828d3c486ee44aaa68240eb3abff289d1c



