CVE-2026-53159
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/06/2026
Last modified:
18/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
misc: fastrpc: fix DMA address corruption due to find_vma misuse<br />
<br />
fastrpc_get_args() uses find_vma() to look up the VMA for a user-provided<br />
pointer and compute a DMA address offset. When the address falls in a gap<br />
before the returned VMA, (ptr & PAGE_MASK) - vma->vm_start underflows,<br />
corrupting the DMA address sent to the DSP.<br />
<br />
Replace find_vma() with vma_lookup(), which returns NULL when the address<br />
is not contained within any VMA.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.1.6 (including) | 5.10.260 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.15.210 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 6.1.176 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.143 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.94 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.18.36 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (including) | 7.0.13 (excluding) |
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc7:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/2d0f47e27c1fa718b29c69aa7c96a2c5161bc2c2
- https://git.kernel.org/stable/c/464c6ad2aa16e1e1df9d559289199356493d1e00
- https://git.kernel.org/stable/c/53e06f8a3c2b085c31bf1284e2ebcb8036e99625
- https://git.kernel.org/stable/c/708c17b52c60fe7a57e73b495bdee50f58feb48c
- https://git.kernel.org/stable/c/7ba7b30ddb04646d4d638f4d8c4718a304bbbddd
- https://git.kernel.org/stable/c/d3e26df2e8eb361e6bef096b2fd565476a1f14c4
- https://git.kernel.org/stable/c/d43afc412d439ffca1567e7ca8652be22f272b3b
- https://git.kernel.org/stable/c/e69e306a4cccb40a73511350cb280825a556ce3c



